Important:
A similar bug was found in Kayako Support Suite by Positive Technologies:
http://packetstormsecurity.org/files/108595/Kayako-Support-Suite-3.70.02-stable-Cross-Site-Scripting.html
Today (20.03.2012) I received a email from Kayako and they reported that bug has been fixed. You can read about it here:
http://wiki.kayako.com/display/DOCS/4.40.985
# Exploit Title: Kayako Fusion Cross Site Scripting
# Date: 17.03.2012
# Author: Sony
# Software Link: http://www.kayako.com/
# Version: all version
# Google Dorks: inurl:Base/UserRegistration/ or intitle:Powered by Kayako Fusion Help Desk Software
# Web Browser : Mozilla Firefox
# Site : http://insecurity.ro
# PoC:
http://st2tea.blogspot.com/2012/03/kayako-fusion-cross-site-scripting.html
..................................................................
Well, we have a cross site scripting in Kayako Fusion.
Our xss in /Tickets/Submit.
Put our code in the all fields and press button Submit.
Click on View Tickets and open our ticket. We can see a Persistent XSS.
A lot of web sites use Kayako Fusion.
We can see Comodo
(SupportSuite v3.70.02)
Avg
(fusion)
etc..
Russian Google Dorks:
intitle:основано на kayako fusion help desk
vineri, 16 martie 2012
Comodo.com and Agv.sg Cross Site Scripting
Etichete:
avg,
comodo.com,
Cross Site Scripting,
Kayako Fusion,
sg
0 comentarii:
Trimiteți un comentariu
Rețineți: Numai membrii acestui blog pot posta comentarii.