Kayako logo
SupportSuite, eSupport and LiveResponse Discussion, troubleshooting and feedback related to Kayako's flagship support desk products SupportSuite, eSupport and LiveResponse.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  (#1) Old
iragrollman Offline
New Member
 
Posts: 1
Join Date: Feb 2007
What's the plan to address reported security issues? - 27-02-2007, 04:42 AM

http://www.frsirt.com/english/advisories/2007/0717

Multiple vulnerabilities have been identified in Kayako eSupport, which could be exploited by attackers to execute arbitrary scripting code. These issues are due to input validation errors in various modules (e.g. "tickets") when processing malformed parameters, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.

The version they tested against is Kayako eSupport version 3.04.10
   
Reply With Quote
  (#2) Old
supportskins Offline
Senior Member
 
supportskins's Avatar
 
Posts: 3,536
Join Date: Aug 2006
Location: Mumbai, India
27-02-2007, 10:00 AM

Has anyone reported this to Kayako?



Professional and Affordable Kayako Skins - Specialists in Kayako Skinning & Customization - Professional Paid Support
Our Skins and Services - http://www.supportskins.com/store/
SupportSkins.com - http://www.supportskins.com/
   
Reply With Quote
  (#3) Old
caitlyntw Offline
Member
 
Posts: 99
Join Date: Jul 2006
06-03-2007, 07:42 AM

I don't think this is a very important issue to them. Several people have reported this, directly to them, on the forum and on the bugtracker.
   
Reply With Quote
  (#4) Old
Olate Offline
Member
 
Posts: 53
Join Date: Sep 2003
Location: England, UK
06-03-2007, 09:20 AM

XSS issues were fixed in the latest stable build 3.10.02 which probably addresses the problems noted in this advisory.
   
Reply With Quote
  (#5) Old
anand Offline
New Member
 
Posts: 1
Join Date: Jun 2007
xss vulnerabilities - 04-06-2007, 06:49 PM

I am using the 3.10.02 version of supportsuite and have found xss vulnerabilities in several places. Have raised a support ticket with example on how to exploit one such vulnerability.

Let me see what response does kayako give.
   
Reply With Quote
  (#6) Old
Jamie Edwards Offline
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,033
Join Date: Jan 2006
Location: United Kingdom
04-06-2007, 06:51 PM

Hi anand,

Can I please have your ticket ID(s)?

Thanks,


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
  • New to the forum? New user's guide here.
  • Submit bug reports here.
  • Submit support tickets via the members area.
  • Submit sales queries either via live chat or via e-mail.
  • There is no official ETA on Version 4.
   
Reply With Quote
Reply

Tags
address, plan

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46