Kayako eSupport version 2.x suffers from cross site scripting and SQL injection flaws. Detailed exploitation given.