Kayako logo
News and Announcements Kayako news and announcements [Subscribe]

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  (#1) Old
Varun Shoor Offline
Chief Executive Officer
 
Varun Shoor's Avatar
 
Posts: 2,829
Join Date: May 2003
Critical Kayako eSupport Vulnerability - 16-05-2005, 06:02 AM

Dear Kayako Customer,

During an audit by our client, We have come to notice of a Critical Security Vulnerability in Version 2.x. The Vulnerability allows a person to remotely run arbitary PHP code. The issue was recently reported and has been immediately looked into by the Kayako team.

This Vulnerability although not Public, *SHOULD NOT* be taken lightly and you are hereby requested to immediately download the latest build from the Members Area and upgrade your existing eSupport to the Latest Version v2.3.5 which fixes the issue.

Hosted Clients:
To avoid any downtime of the hosted services, the helpdesk shall be upgraded in due time. You should receive an email notice as soon as it is upgraded.

If you have any questions please Email support@kayako.com.

Upgrade Instructions
---------------------

Upgrading from v2.3.1 to v2.3.5 Stable
=============================================
* IMPORTANT! Backup BOTH your Database (mysqldump) and your Files before proceeding.
* Replace all your existing files with the new ones in upload_zend/upload_ioncube directory EXCEPT for config.php
* REMOVE admin/setup.php
* Make sure BOTH your config.php AND key.php are in admin/ directory after you have replaced the files

Upgrading from v2.2.5 to v2.3.5 Stable
=============================================
* IMPORTANT! Backup BOTH your Database (mysqldump) and your Files before proceeding.
* Replace all your existing files with the new ones in upload_zend/upload_ioncube directory EXCEPT for config.php
* REMOVE admin/setup.php
* Make sure BOTH your config.php AND key.php are in admin/ directory after you have replaced the files

Upgrading from v2.2 to v2.3.5 Stable
=============================================
* IMPORTANT! Backup BOTH your Database (mysqldump) and your Files before proceeding.
* Replace all your existing files with the new ones in upload_zend/upload_ioncube directory EXCEPT for config.php
* REMOVE admin/setup.php
* Make sure BOTH your config.php AND key.php are in admin/ directory after you have replaced the files
* Upload the file "upgrade_v2.2_to_v2.3.php" from your upgrade/ directory over to admin/ directory and run it from your web browser
* Follow the steps, it should finish without any issues.
* Delete "upgrade_v2.2_to_v2.3.php" from your admin/ directory

Upgrading from v2.1.x to v2.3.5 Stable
=============================================
* IMPORTANT! Backup BOTH your Database (mysqldump) and your Files before proceeding.
* Replace all your existing files with the new ones in upload_zend/upload_ioncube directory EXCEPT for config.php
* REMOVE admin/setup.php
* Make sure BOTH your config.php AND key.php are in admin/ directory after you have replaced the files
* Upload the file "upgrade_v2.1.x_to_v2.3.php" from your upgrade/ directory over to admin/ directory and run it from your web browser
* Follow the steps, it should finish without any issues.
* Delete "upgrade_v2.1.x_to_v2.3.php" from your admin/ directory

Regards,

The Kayako Team


Varun Shoor (varun.shoor ]at[ kayako.com)
----------------------------------------------------------------
---
   
Reply With Quote
Reply

Tags
critical, esupport, vulnerability
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Free eSupport QuickTicket Script v1.0 for Kayako eSupport netarus Modifications & Addon Releases 13 08-01-2008 01:40 PM
Tutorial to setup Kayako eSupport pipe parser with cPanel Webber SupportSuite, eSupport and LiveResponse 2 29-08-2006 12:37 PM
eSupport v2.3.1 Stable Released - (XSS Vulnerability Fix) Varun Shoor News and Announcements 2 08-02-2005 02:12 PM
eSupport v2.2 RC2 Released Varun Shoor Technical Chat 1 11-06-2004 10:24 PM



Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46