Security Advisory

CVE-2005-4638

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-01-09 23:00:00
Last updated 2024-08-07 23:53:27
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

index.php in Kayako SupportSuite 3.00.26 and earlier allow remote attackers to obtain the full path via (1) _a and (2) newsid parameters in the news module, (3) downloaditemid parameter in the downloads module, and (4) kbarticleid parameter in the knowledgebase module.