Skip to content
Noroxi

livezilla records

21 published records for vendor livezilla.

All records

21 records
  • LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 27%

    livezilla · livezillaJan 13, 2020

  • CVE-2020-9758
    39Monitor

    An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk).

    CriticalCVSS 9.6Proof of conceptEPSS 2%

    livezilla · livezillaMar 9, 2020

  • LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.

    CriticalCVSS 9.8No exploitEPSS 1%

    livezilla · livezillaJun 25, 2019

  • LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.

    CriticalCVSS 9.8No exploitEPSS 1%

    livezilla · livezillaJun 24, 2019

  • LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.

    HighCVSS 8.8No exploitEPSS 1%

    livezilla · livezillaJun 25, 2019

  • CVE-2013-7034
    30Monitor

    The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP co

    HighCVSS 7.5No exploitEPSS 2%

    livezilla · livezillaMay 5, 2014

  • LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.

    MediumCVSS 6.1Proof of conceptEPSS 9%

    livezilla · livezillaJun 25, 2019

  • CVE-2013-7385
    27Monitor

    LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/

    MediumCVSS 6.8No exploitEPSS 1%

    livezilla · livezillaMay 19, 2014

  • Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web sc

    MediumCVSS 6.1No exploitEPSS 1%

    livezilla · livezillaJan 18, 2018

  • LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.

    MediumCVSS 6.1No exploitEPSS 1%

    livezilla · livezillaJun 25, 2019

  • LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject.

    MediumCVSS 6.1No exploitEPSS 1%

    livezilla · livezillaJun 25, 2019

  • chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.

    MediumCVSS 6.1No exploitEPSS 1%

    livezilla · livezillaMay 16, 2018

  • LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of th

    MediumCVSS 5.9No exploitEPSS 1%

    livezilla · livezillaJun 24, 2019

  • CVE-2013-6224
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.1.0 allow remote attackers to inject arbitrary web script or HTM

    MediumCVSS 4.3No exploitEPSS 2%

    livezilla · livezillaDec 10, 2013

  • CVE-2013-7003
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitrary web script or HTM

    MediumCVSS 4.3No exploitEPSS 2%

    livezilla · livezillaMay 5, 2014

  • CVE-2013-7032
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow remote attackers to i

    MediumCVSS 4.3No exploitEPSS 2%

    livezilla · livezillaFeb 14, 2014

  • CVE-2010-4276
    18Monitor

    Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allows

    MediumCVSS 4.3Proof of conceptEPSS 2%

    livezilla · livezillaDec 30, 2010

  • CVE-2009-4450
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web script or

    MediumCVSS 4.3Proof of conceptEPSS 1%

    livezilla · livezillaDec 29, 2009

  • CVE-2013-7002
    17Monitor

    Cross-site scripting (XSS) vulnerability in mobile/php/translation/index.php in LiveZilla before 5.1.1.0 allows remote attackers to inject a

    MediumCVSS 4.3No exploitEPSS 1%

    livezilla · livezillaDec 20, 2013

  • CVE-2013-7033
    17Monitor

    LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which might

    MediumCVSS 4.3No exploitEPSS 1%

    livezilla · livezillaMay 19, 2014

  • LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local users to obtain access b

    LowCVSS 2.1No exploitEPSS 0%

    livezilla · livezillaJun 9, 2014