CVE-2005-2461

critical

Description

Multiple SQL injection vulnerabilities in the calendar feature in Kayako liveResponse 2.x allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) date parameter.

References

http://www.securityfocus.com/bid/14425

http://www.osvdb.org/18396

http://www.gulftech.org/?node=research&article_id=00092-07302005

http://secunia.com/advisories/16286

http://marc.info/?l=bugtraq&m=112274359718863&w=2

Details

Source: Mitre, NVD

Published: 2005-12-31

Updated: 2016-10-18

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical