vineri, 16 martie 2012

Comodo.com and Agv.sg Cross Site Scripting

Important:

A similar bug was found in Kayako Support Suite by Positive Technologies:

http://packetstormsecurity.org/files/108595/Kayako-Support-Suite-3.70.02-stable-Cross-Site-Scripting.html


Today (20.03.2012) I received a email from Kayako and they reported that bug has been fixed. You can read about it here:

http://wiki.kayako.com/display/DOCS/4.40.985


# Exploit Title: Kayako Fusion Cross Site Scripting
# Date: 17.03.2012
# Author: Sony

# Software Link: http://www.kayako.com/
# Version: all version
# Google Dorks: inurl:Base/UserRegistration/ or intitle:Powered by Kayako Fusion Help Desk Software
# Web Browser : Mozilla Firefox

# Site : http://insecurity.ro
# PoC:
http://st2tea.blogspot.com/2012/03/kayako-fusion-cross-site-scripting.html
..................................................................

Well, we have a cross site scripting in Kayako Fusion.

Our xss in /Tickets/Submit.

Put our code in the all fields and press button Submit.

Click on View Tickets and open our ticket. We can see a Persistent XSS.




A lot of web sites use Kayako Fusion.

We can see Comodo

(SupportSuite v3.70.02)


Avg
(fusion)


etc..

Russian Google Dorks:

intitle:основано на kayako fusion help desk

0 comentarii:

Trimiteți un comentariu

Rețineți: Numai membrii acestui blog pot posta comentarii.