Reply
 
Thread Tools Search this Thread Display Modes
  #1
Old     
Varun [K] (Offline)
Administrator
 
Varun [K]'s Avatar
 
Posts: 3,878
Join Date: May 2003
Send a message via AIM to Varun [K]Send a message via Yahoo to Varun [K]
eSupport v2.3.1 Stable Released - (XSS Vulnerability Fix) - 12-25-2004, 11:24 PM

Kayako eSupport XSS Vulnerability
==============================

A Security Vulnerability has been discovered in all eSupport versions prior to v2.3. The vulnerability allows a person to execute a Javascript on clients computer to retreive the ticket key. This vulnerability can be exploited only if the client opens a URL posted by the attacker.

Please download the build from Members Area only after you see v2.3.1 as version number. The files are still being committed as we are sending this announcement. If you have any questions please email support AT kayako.com, You can also directly contact me at varun AT kayako.com or over IM (Details listed in Profile). We would like to thank James from GulfTech for discovering these vulnerabilities.

Upgrading from v2.3 to v2.3.1 Stable
=============================================
* IMPORTANT! Backup BOTH your Database (mysqldump) and your Files before proceeding.
* Replace all your existing files with the new ones in upload_zend/upload_ioncube directory
* REMOVE admin/setup.php
* Make sure BOTH your config.php AND key.php are in admin/ directory after you have replaced the files

Upgrading from v2.2.5 to v2.3.1 Stable
=============================================
* IMPORTANT! Backup BOTH your Database (mysqldump) and your Files before proceeding.
* Replace all your existing files with the new ones in upload_zend/upload_ioncube directory
* REMOVE admin/setup.php
* Make sure BOTH your config.php AND key.php are in admin/ directory after you have replaced the files

Upgrading from v2.2 to v2.3.1 Stable
=============================================
* IMPORTANT! Backup BOTH your Database (mysqldump) and your Files before proceeding.
* Replace all your existing files with the new ones in upload_zend/upload_ioncube directory
* REMOVE admin/setup.php
* Make sure BOTH your config.php AND key.php are in admin/ directory after you have replaced the files
* Upload the file "upgrade_v2.2_to_v2.3.php" from your upgrade/ directory over to admin/ directory and run it from your web browser
* Follow the steps, it should finish without any issues.
* Delete "upgrade_v2.2_to_v2.3.php" from your admin/ directory

Upgrading from v2.1.x to v2.3.1 Stable
=============================================
* IMPORTANT! Backup BOTH your Database (mysqldump) and your Files before proceeding.
* Replace all your existing files with the new ones in upload_zend/upload_ioncube directory
* REMOVE admin/setup.php
* Make sure BOTH your config.php AND key.php are in admin/ directory after you have replaced the files
* Upload the file "upgrade_v2.1.x_to_v2.3.php" from your upgrade/ directory over to admin/ directory and run it from your web browser
* Follow the steps, it should finish without any issues.
* Delete "upgrade_v1.x_to_v2.3.php" from your admin/ directory
 
Reply With Quote
  #2
Old     
Varun [K] (Offline)
Administrator
 
Varun [K]'s Avatar
 
Posts: 3,878
Join Date: May 2003
Send a message via AIM to Varun [K]Send a message via Yahoo to Varun [K]
12-25-2004, 11:25 PM

This version also fixes the issues with PHP 4.3.10

Regards,

Varun Shoor
 
Reply With Quote
  #3
Old     
Neil-UKWSD (Offline)
 
Neil-UKWSD's Avatar
 
Posts: 1,855
Join Date: Jun 2003
Location: United Kingdom
02-08-2005, 09:12 AM

If you are using WinZip to extract the files please ensure you enable "TAR file smart CR/LF conversion" under Options > Configurations > Miscellaneous in WinZip before hand.

Also remember to CHMOD pop3pipe.php and autoclose.php to CHMOD 755 so they can be executed by cron.


Neil Wood | UKWSD

UK Web Hosting from £20.99 (+VAT) per year
http://ukwebsolutionsdirect.co.uk
 
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Critical Kayako eSupport Vulnerability Varun [K] Announcements 0 05-16-2005 01:02 AM
New Security Vulnerability in eSupport v2.3.1? xyzed How do I/Troubleshooting 3 03-23-2005 05:03 PM
eSupport v2.2 Stable Released Varun [K] Announcements 3 06-23-2004 06:39 PM
eSupport v2.2 RC2 Released Varun [K] Announcements 1 06-11-2004 05:24 PM
eSupport v2.1.6 and InstaAlert Released! Varun [K] Announcements 5 10-11-2003 01:48 AM



Powered by vBulletin Version 3.5.3
Copyright ©2000 - 2006, Jelsoft Enterprises Ltd.
vBulletin Skin developed by: vBStyles.com