livezilla records
21 published records for vendor livezilla.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-310 Cryptographic Issues2
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2013-6225Proof of concept | LiveZilla 5.0.1.4 has a Remote Code Execution vulnerabilitylivezilla · livezilla · CWE-22 | Critical9.8 | — | 26.6% | Jan 13, 2020 |
39Monitor | CVE-2020-9758Proof of concept | An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk).livezilla · livezilla · CWE-79 | Critical9.6 | — | 2.5% | Mar 9, 2020 |
39Monitor | CVE-2019-12960No exploit | LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.livezilla · livezilla · CWE-89 | Critical9.8 | — | 1.4% | Jun 25, 2019 |
39Monitor | CVE-2019-12939No exploit | LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.livezilla · livezilla · CWE-89 | Critical9.8 | — | 1.4% | Jun 24, 2019 |
35Monitor | CVE-2019-12961No exploit | LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.livezilla · livezilla · CWE-1236 | High8.8 | — | 1.4% | Jun 25, 2019 |
30Monitor | CVE-2013-7034No exploit | The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP colivezilla · livezilla · CWE-94 | High7.5 | — | 1.6% | May 5, 2014 |
27Monitor | CVE-2019-12962Proof of concept | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.livezilla · livezilla · CWE-79 | Medium6.1 | — | 9.1% | Jun 25, 2019 |
27Monitor | CVE-2013-7385No exploit | LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/livezilla · livezilla · CWE-310 | Medium6.8 | — | 1.3% | May 19, 2014 |
24Monitor | CVE-2017-15869No exploit | Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web sclivezilla · livezilla · CWE-79 | Medium6.1 | — | 1.3% | Jan 18, 2018 |
24Monitor | CVE-2019-12963No exploit | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.livezilla · livezilla · CWE-79 | Medium6.1 | — | 0.8% | Jun 25, 2019 |
24Monitor | CVE-2019-12964No exploit | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject.livezilla · livezilla · CWE-79 | Medium6.1 | — | 0.8% | Jun 25, 2019 |
24Monitor | CVE-2018-10810No exploit | chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.livezilla · livezilla · CWE-79 | Medium6.1 | — | 0.6% | May 16, 2018 |
23Monitor | CVE-2019-12940No exploit | LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of thlivezilla · livezilla · CWE-770 | Medium5.9 | — | 1.1% | Jun 24, 2019 |
18Monitor | CVE-2013-6224No exploit | Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.1.0 allow remote attackers to inject arbitrary web script or HTMlivezilla · livezilla · CWE-79 | Medium4.3 | — | 2.2% | Dec 10, 2013 |
18Monitor | CVE-2013-7003No exploit | Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitrary web script or HTMlivezilla · livezilla · CWE-79 | Medium4.3 | — | 1.9% | May 5, 2014 |
18Monitor | CVE-2013-7032No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow remote attackers to ilivezilla · livezilla · CWE-79 | Medium4.3 | — | 1.8% | Feb 14, 2014 |
18Monitor | CVE-2010-4276Proof of concept | Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allowslivezilla · livezilla · CWE-79 | Medium4.3 | — | 1.7% | Dec 30, 2010 |
17Monitor | CVE-2009-4450Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web script orlivezilla · livezilla · CWE-79 | Medium4.3 | — | 1.5% | Dec 29, 2009 |
17Monitor | CVE-2013-7002No exploit | Cross-site scripting (XSS) vulnerability in mobile/php/translation/index.php in LiveZilla before 5.1.1.0 allows remote attackers to inject alivezilla · livezilla · CWE-79 | Medium4.3 | — | 1.2% | Dec 20, 2013 |
17Monitor | CVE-2013-7033No exploit | LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which mightlivezilla · livezilla · CWE-310 | Medium4.3 | — | 1.2% | May 19, 2014 |
8Monitor | CVE-2013-6223No exploit | LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local users to obtain access blivezilla · livezilla · CWE-255 | Low2.1 | — | 0.5% | Jun 9, 2014 |
- CVE-2013-622547Plan
LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 27%livezilla · livezillaJan 13, 2020
- CVE-2020-975839Monitor
An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk).
CriticalCVSS 9.6Proof of conceptEPSS 2%livezilla · livezillaMar 9, 2020
- CVE-2019-1296039Monitor
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.
CriticalCVSS 9.8No exploitEPSS 1%livezilla · livezillaJun 25, 2019
- CVE-2019-1293939Monitor
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.
CriticalCVSS 9.8No exploitEPSS 1%livezilla · livezillaJun 24, 2019
- CVE-2019-1296135Monitor
LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.
HighCVSS 8.8No exploitEPSS 1%livezilla · livezillaJun 25, 2019
- CVE-2013-703430Monitor
The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP co
HighCVSS 7.5No exploitEPSS 2%livezilla · livezillaMay 5, 2014
- CVE-2019-1296227Monitor
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
MediumCVSS 6.1Proof of conceptEPSS 9%livezilla · livezillaJun 25, 2019
- CVE-2013-738527Monitor
LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/
MediumCVSS 6.8No exploitEPSS 1%livezilla · livezillaMay 19, 2014
- CVE-2017-1586924Monitor
Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web sc
MediumCVSS 6.1No exploitEPSS 1%livezilla · livezillaJan 18, 2018
- CVE-2019-1296324Monitor
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.
MediumCVSS 6.1No exploitEPSS 1%livezilla · livezillaJun 25, 2019
- CVE-2019-1296424Monitor
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject.
MediumCVSS 6.1No exploitEPSS 1%livezilla · livezillaJun 25, 2019
- CVE-2018-1081024Monitor
chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.
MediumCVSS 6.1No exploitEPSS 1%livezilla · livezillaMay 16, 2018
- CVE-2019-1294023Monitor
LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of th
MediumCVSS 5.9No exploitEPSS 1%livezilla · livezillaJun 24, 2019
- CVE-2013-622418Monitor
Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.1.0 allow remote attackers to inject arbitrary web script or HTM
MediumCVSS 4.3No exploitEPSS 2%livezilla · livezillaDec 10, 2013
- CVE-2013-700318Monitor
Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitrary web script or HTM
MediumCVSS 4.3No exploitEPSS 2%livezilla · livezillaMay 5, 2014
- CVE-2013-703218Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow remote attackers to i
MediumCVSS 4.3No exploitEPSS 2%livezilla · livezillaFeb 14, 2014
- CVE-2010-427618Monitor
Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allows
MediumCVSS 4.3Proof of conceptEPSS 2%livezilla · livezillaDec 30, 2010
- CVE-2009-445017Monitor
Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web script or
MediumCVSS 4.3Proof of conceptEPSS 1%livezilla · livezillaDec 29, 2009
- CVE-2013-700217Monitor
Cross-site scripting (XSS) vulnerability in mobile/php/translation/index.php in LiveZilla before 5.1.1.0 allows remote attackers to inject a
MediumCVSS 4.3No exploitEPSS 1%livezilla · livezillaDec 20, 2013
- CVE-2013-703317Monitor
LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which might
MediumCVSS 4.3No exploitEPSS 1%livezilla · livezillaMay 19, 2014
- CVE-2013-62238Monitor
LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local users to obtain access b
LowCVSS 2.1No exploitEPSS 0%livezilla · livezillaJun 9, 2014