Vulnerabilities > CVE-2006-4884 - Cross-Site Scripting vulnerability in Idevspot Isupport 1.8

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
idevspot
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the ticket_id parameter in support/open_tickets.php, and (3) the cons_page_title parameter in index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Vulnerable Configurations

Part Description Count
Application
Idevspot
1

Exploit-Db

  • descriptionIDevSpot iSupport 1.8 open_tickets.php ticket_id Parameter XSS. CVE-2006-4884. Webapps exploit for php platform
    idEDB-ID:28516
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporters3rv3r_hack3r
    sourcehttps://www.exploit-db.com/download/28516/
    titleIDevSpot iSupport 1.8 open_tickets.php ticket_id Parameter XSS
  • descriptionIDevSpot iSupport 1.8 rightbar.php suser Parameter XSS. CVE-2006-4884. Webapps exploit for php platform
    idEDB-ID:28515
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporters3rv3r_hack3r
    sourcehttps://www.exploit-db.com/download/28515/
    titleIDevSpot iSupport 1.8 rightbar.php suser Parameter XSS
  • descriptionIDevSpot iSupport 1.8 index.php cons_page_title Parameter XSS. CVE-2006-4884 . Webapps exploit for php platform
    idEDB-ID:28517
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporters3rv3r_hack3r
    sourcehttps://www.exploit-db.com/download/28517/
    titleIDevSpot iSupport 1.8 index.php cons_page_title Parameter XSS