Записи livezilla
21 опубликованных записей вендора livezilla.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-310 Cryptographic Issues2
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2013-6225Proof of concept | LiveZilla 5.0.1.4 has a Remote Code Execution vulnerabilitylivezilla · livezilla · CWE-22 | Критическая9,8 | — | 26,6 % | 13 янв. 2020 г. |
39Наблюдать | CVE-2020-9758Proof of concept | An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk).livezilla · livezilla · CWE-79 | Критическая9,6 | — | 2,5 % | 9 мар. 2020 г. |
39Наблюдать | CVE-2019-12960Эксплойта нет | LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.livezilla · livezilla · CWE-89 | Критическая9,8 | — | 1,4 % | 25 июн. 2019 г. |
39Наблюдать | CVE-2019-12939Эксплойта нет | LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.livezilla · livezilla · CWE-89 | Критическая9,8 | — | 1,4 % | 24 июн. 2019 г. |
35Наблюдать | CVE-2019-12961Эксплойта нет | LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.livezilla · livezilla · CWE-1236 | Высокая8,8 | — | 1,4 % | 25 июн. 2019 г. |
30Наблюдать | CVE-2013-7034Эксплойта нет | The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP colivezilla · livezilla · CWE-94 | Высокая7,5 | — | 1,6 % | 5 мая 2014 г. |
27Наблюдать | CVE-2019-12962Proof of concept | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.livezilla · livezilla · CWE-79 | Средняя6,1 | — | 9,1 % | 25 июн. 2019 г. |
27Наблюдать | CVE-2013-7385Эксплойта нет | LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/livezilla · livezilla · CWE-310 | Средняя6,8 | — | 1,3 % | 19 мая 2014 г. |
24Наблюдать | CVE-2017-15869Эксплойта нет | Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web sclivezilla · livezilla · CWE-79 | Средняя6,1 | — | 1,3 % | 18 янв. 2018 г. |
24Наблюдать | CVE-2019-12963Эксплойта нет | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.livezilla · livezilla · CWE-79 | Средняя6,1 | — | 0,8 % | 25 июн. 2019 г. |
24Наблюдать | CVE-2019-12964Эксплойта нет | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject.livezilla · livezilla · CWE-79 | Средняя6,1 | — | 0,8 % | 25 июн. 2019 г. |
24Наблюдать | CVE-2018-10810Эксплойта нет | chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.livezilla · livezilla · CWE-79 | Средняя6,1 | — | 0,6 % | 16 мая 2018 г. |
23Наблюдать | CVE-2019-12940Эксплойта нет | LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of thlivezilla · livezilla · CWE-770 | Средняя5,9 | — | 1,1 % | 24 июн. 2019 г. |
18Наблюдать | CVE-2013-6224Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.1.0 allow remote attackers to inject arbitrary web script or HTMlivezilla · livezilla · CWE-79 | Средняя4,3 | — | 2,2 % | 10 дек. 2013 г. |
18Наблюдать | CVE-2013-7003Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitrary web script or HTMlivezilla · livezilla · CWE-79 | Средняя4,3 | — | 1,9 % | 5 мая 2014 г. |
18Наблюдать | CVE-2013-7032Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow remote attackers to ilivezilla · livezilla · CWE-79 | Средняя4,3 | — | 1,8 % | 14 февр. 2014 г. |
18Наблюдать | CVE-2010-4276Proof of concept | Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allowslivezilla · livezilla · CWE-79 | Средняя4,3 | — | 1,7 % | 30 дек. 2010 г. |
17Наблюдать | CVE-2009-4450Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web script orlivezilla · livezilla · CWE-79 | Средняя4,3 | — | 1,5 % | 29 дек. 2009 г. |
17Наблюдать | CVE-2013-7002Эксплойта нет | Cross-site scripting (XSS) vulnerability in mobile/php/translation/index.php in LiveZilla before 5.1.1.0 allows remote attackers to inject alivezilla · livezilla · CWE-79 | Средняя4,3 | — | 1,2 % | 20 дек. 2013 г. |
17Наблюдать | CVE-2013-7033Эксплойта нет | LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which mightlivezilla · livezilla · CWE-310 | Средняя4,3 | — | 1,2 % | 19 мая 2014 г. |
8Наблюдать | CVE-2013-6223Эксплойта нет | LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local users to obtain access blivezilla · livezilla · CWE-255 | Низкая2,1 | — | 0,5 % | 9 июн. 2014 г. |
- CVE-2013-622547В плане
LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 27 %livezilla · livezilla13 янв. 2020 г.
- CVE-2020-975839Наблюдать
An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk).
КритическаяCVSS 9,6Proof of conceptEPSS 2 %livezilla · livezilla9 мар. 2020 г.
- CVE-2019-1296039Наблюдать
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %livezilla · livezilla25 июн. 2019 г.
- CVE-2019-1293939Наблюдать
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %livezilla · livezilla24 июн. 2019 г.
- CVE-2019-1296135Наблюдать
LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %livezilla · livezilla25 июн. 2019 г.
- CVE-2013-703430Наблюдать
The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP co
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %livezilla · livezilla5 мая 2014 г.
- CVE-2019-1296227Наблюдать
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
СредняяCVSS 6,1Proof of conceptEPSS 9 %livezilla · livezilla25 июн. 2019 г.
- CVE-2013-738527Наблюдать
LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/
СредняяCVSS 6,8Эксплойта нетEPSS 1 %livezilla · livezilla19 мая 2014 г.
- CVE-2017-1586924Наблюдать
Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web sc
СредняяCVSS 6,1Эксплойта нетEPSS 1 %livezilla · livezilla18 янв. 2018 г.
- CVE-2019-1296324Наблюдать
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %livezilla · livezilla25 июн. 2019 г.
- CVE-2019-1296424Наблюдать
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %livezilla · livezilla25 июн. 2019 г.
- CVE-2018-1081024Наблюдать
chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %livezilla · livezilla16 мая 2018 г.
- CVE-2019-1294023Наблюдать
LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of th
СредняяCVSS 5,9Эксплойта нетEPSS 1 %livezilla · livezilla24 июн. 2019 г.
- CVE-2013-622418Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.1.0 allow remote attackers to inject arbitrary web script or HTM
СредняяCVSS 4,3Эксплойта нетEPSS 2 %livezilla · livezilla10 дек. 2013 г.
- CVE-2013-700318Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitrary web script or HTM
СредняяCVSS 4,3Эксплойта нетEPSS 2 %livezilla · livezilla5 мая 2014 г.
- CVE-2013-703218Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow remote attackers to i
СредняяCVSS 4,3Эксплойта нетEPSS 2 %livezilla · livezilla14 февр. 2014 г.
- CVE-2010-427618Наблюдать
Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allows
СредняяCVSS 4,3Proof of conceptEPSS 2 %livezilla · livezilla30 дек. 2010 г.
- CVE-2009-445017Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web script or
СредняяCVSS 4,3Proof of conceptEPSS 1 %livezilla · livezilla29 дек. 2009 г.
- CVE-2013-700217Наблюдать
Cross-site scripting (XSS) vulnerability in mobile/php/translation/index.php in LiveZilla before 5.1.1.0 allows remote attackers to inject a
СредняяCVSS 4,3Эксплойта нетEPSS 1 %livezilla · livezilla20 дек. 2013 г.
- CVE-2013-703317Наблюдать
LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which might
СредняяCVSS 4,3Эксплойта нетEPSS 1 %livezilla · livezilla19 мая 2014 г.
- CVE-2013-62238Наблюдать
LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local users to obtain access b
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %livezilla · livezilla9 июн. 2014 г.