CVE-2012-3233 Information

Description

Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako Fusion 4.40.1148 and possibly before 4.50.1581 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

Reference

http://archives.neohapsis.com/archives/bugtraq/2012-09/0022.html http://osvdb.org/85189 http://secunia.com/advisories/50366 http://wiki.kayako.com/display/DOCS/4.50.1581 http://wiki.kayako.com/display/DOCS/4.50.1619 http://www.securityfocus.com/bid/55417 https://exchange.xforce.ibmcloud.com/vulnerabilities/78314 https://www.htbridge.com/advisory/HTB23095

Share on: