livezilla kayıtları
livezilla üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-310 Cryptographic Issues2
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
47Planlayın | CVE-2013-6225Kavram kanıtı | LiveZilla 5.0.1.4 has a Remote Code Execution vulnerabilitylivezilla · livezilla · CWE-22 | Kritik9,8 | — | %26,6 | 13 Oca 2020 |
39İzleyin | CVE-2020-9758Kavram kanıtı | An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk).livezilla · livezilla · CWE-79 | Kritik9,6 | — | %2,5 | 9 Mar 2020 |
39İzleyin | CVE-2019-12960İstismar yok | LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.livezilla · livezilla · CWE-89 | Kritik9,8 | — | %1,4 | 25 Haz 2019 |
39İzleyin | CVE-2019-12939İstismar yok | LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.livezilla · livezilla · CWE-89 | Kritik9,8 | — | %1,4 | 24 Haz 2019 |
35İzleyin | CVE-2019-12961İstismar yok | LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.livezilla · livezilla · CWE-1236 | Yüksek8,8 | — | %1,4 | 25 Haz 2019 |
30İzleyin | CVE-2013-7034İstismar yok | The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP colivezilla · livezilla · CWE-94 | Yüksek7,5 | — | %1,6 | 5 May 2014 |
27İzleyin | CVE-2019-12962Kavram kanıtı | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.livezilla · livezilla · CWE-79 | Orta6,1 | — | %9,1 | 25 Haz 2019 |
27İzleyin | CVE-2013-7385İstismar yok | LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/livezilla · livezilla · CWE-310 | Orta6,8 | — | %1,3 | 19 May 2014 |
24İzleyin | CVE-2017-15869İstismar yok | Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web sclivezilla · livezilla · CWE-79 | Orta6,1 | — | %1,3 | 18 Oca 2018 |
24İzleyin | CVE-2019-12963İstismar yok | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.livezilla · livezilla · CWE-79 | Orta6,1 | — | %0,8 | 25 Haz 2019 |
24İzleyin | CVE-2019-12964İstismar yok | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject.livezilla · livezilla · CWE-79 | Orta6,1 | — | %0,8 | 25 Haz 2019 |
24İzleyin | CVE-2018-10810İstismar yok | chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.livezilla · livezilla · CWE-79 | Orta6,1 | — | %0,6 | 16 May 2018 |
23İzleyin | CVE-2019-12940İstismar yok | LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of thlivezilla · livezilla · CWE-770 | Orta5,9 | — | %1,1 | 24 Haz 2019 |
18İzleyin | CVE-2013-6224İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.1.0 allow remote attackers to inject arbitrary web script or HTMlivezilla · livezilla · CWE-79 | Orta4,3 | — | %2,2 | 10 Ara 2013 |
18İzleyin | CVE-2013-7003İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitrary web script or HTMlivezilla · livezilla · CWE-79 | Orta4,3 | — | %1,9 | 5 May 2014 |
18İzleyin | CVE-2013-7032İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow remote attackers to ilivezilla · livezilla · CWE-79 | Orta4,3 | — | %1,8 | 14 Şub 2014 |
18İzleyin | CVE-2010-4276Kavram kanıtı | Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allowslivezilla · livezilla · CWE-79 | Orta4,3 | — | %1,7 | 30 Ara 2010 |
17İzleyin | CVE-2009-4450Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web script orlivezilla · livezilla · CWE-79 | Orta4,3 | — | %1,5 | 29 Ara 2009 |
17İzleyin | CVE-2013-7002İstismar yok | Cross-site scripting (XSS) vulnerability in mobile/php/translation/index.php in LiveZilla before 5.1.1.0 allows remote attackers to inject alivezilla · livezilla · CWE-79 | Orta4,3 | — | %1,2 | 20 Ara 2013 |
17İzleyin | CVE-2013-7033İstismar yok | LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which mightlivezilla · livezilla · CWE-310 | Orta4,3 | — | %1,2 | 19 May 2014 |
8İzleyin | CVE-2013-6223İstismar yok | LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local users to obtain access blivezilla · livezilla · CWE-255 | Düşük2,1 | — | %0,5 | 9 Haz 2014 |
- CVE-2013-622547Planlayın
LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %27livezilla · livezilla13 Oca 2020
- CVE-2020-975839İzleyin
An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk).
KritikCVSS 9,6Kavram kanıtıEPSS %2livezilla · livezilla9 Mar 2020
- CVE-2019-1296039İzleyin
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.
KritikCVSS 9,8İstismar yokEPSS %1livezilla · livezilla25 Haz 2019
- CVE-2019-1293939İzleyin
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.
KritikCVSS 9,8İstismar yokEPSS %1livezilla · livezilla24 Haz 2019
- CVE-2019-1296135İzleyin
LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.
YüksekCVSS 8,8İstismar yokEPSS %1livezilla · livezilla25 Haz 2019
- CVE-2013-703430İzleyin
The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP co
YüksekCVSS 7,5İstismar yokEPSS %2livezilla · livezilla5 May 2014
- CVE-2019-1296227İzleyin
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
OrtaCVSS 6,1Kavram kanıtıEPSS %9livezilla · livezilla25 Haz 2019
- CVE-2013-738527İzleyin
LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/
OrtaCVSS 6,8İstismar yokEPSS %1livezilla · livezilla19 May 2014
- CVE-2017-1586924İzleyin
Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web sc
OrtaCVSS 6,1İstismar yokEPSS %1livezilla · livezilla18 Oca 2018
- CVE-2019-1296324İzleyin
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.
OrtaCVSS 6,1İstismar yokEPSS %1livezilla · livezilla25 Haz 2019
- CVE-2019-1296424İzleyin
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject.
OrtaCVSS 6,1İstismar yokEPSS %1livezilla · livezilla25 Haz 2019
- CVE-2018-1081024İzleyin
chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.
OrtaCVSS 6,1İstismar yokEPSS %1livezilla · livezilla16 May 2018
- CVE-2019-1294023İzleyin
LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of th
OrtaCVSS 5,9İstismar yokEPSS %1livezilla · livezilla24 Haz 2019
- CVE-2013-622418İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.1.0 allow remote attackers to inject arbitrary web script or HTM
OrtaCVSS 4,3İstismar yokEPSS %2livezilla · livezilla10 Ara 2013
- CVE-2013-700318İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitrary web script or HTM
OrtaCVSS 4,3İstismar yokEPSS %2livezilla · livezilla5 May 2014
- CVE-2013-703218İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow remote attackers to i
OrtaCVSS 4,3İstismar yokEPSS %2livezilla · livezilla14 Şub 2014
- CVE-2010-427618İzleyin
Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allows
OrtaCVSS 4,3Kavram kanıtıEPSS %2livezilla · livezilla30 Ara 2010
- CVE-2009-445017İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web script or
OrtaCVSS 4,3Kavram kanıtıEPSS %1livezilla · livezilla29 Ara 2009
- CVE-2013-700217İzleyin
Cross-site scripting (XSS) vulnerability in mobile/php/translation/index.php in LiveZilla before 5.1.1.0 allows remote attackers to inject a
OrtaCVSS 4,3İstismar yokEPSS %1livezilla · livezilla20 Ara 2013
- CVE-2013-703317İzleyin
LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which might
OrtaCVSS 4,3İstismar yokEPSS %1livezilla · livezilla19 May 2014
- CVE-2013-62238İzleyin
LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local users to obtain access b
DüşükCVSS 2,1İstismar yokEPSS %0livezilla · livezilla9 Haz 2014