Cory Support “q” SQL Injection
Application: Cory Support
Affected Version: version 1.0 and other versions.
Vendor’s URL: Cory Support
Bug Type: SQL Injection
Risk Level: Critical
Solution:
No official solution is currently available.
Application: Cory Support
Affected Version: version 1.0 and other versions.
Vendor’s URL: Cory Support
Bug Type: SQL Injection
Risk Level: Critical
Solution:
No official solution is currently available.
Application: e-ticketing
Affected Version: version downloaded on 2012-04-05, other versions are not affected.
Vendor’s URL: e-ticketing
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
Application: PHP Live!
Affected Version: version 3.3 and other versions.
Vendor’s URL: PHP Live!
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
Application: PHP Live Helper
Affected Version: version 2.0.1 and other versions.
Vendor’s URL: PHP Live Helper
Bug Type: SQL Injection
Risk Level: Critcal
Solution:
Update to version 2.1.0.
Application: Kayako
Affected Version: version 3.20.02 and prior versions
Vendor’s URL: SupportSuite
Bug Type: SQL Injection and Cross Site Scripting
Risk Level: Critical
Solution:
Fixed in version 3.30.00 RC3.
Filter malicious characters and character sequences in a web proxy.
Application: h2desk Support System
Affected Version:
Vendor’s URL: http://www.heathcosoft.com/h2desk/
Bug Type: Security Bypass
Risk Level: Medium
Solution:
Grant trusted users to access
Application: PHP Live!
Affected Version: 3.2.2 or other versions may be affected
Vendor’s URL: http://www.phplivesupport.com/
Bug Type: Cross-Site Scripting
Risk Level: Medium
Solution:
Waiting for updates or patches from vendor