4.3
CVSSv2

CVE-2013-7033

Published: 19/05/2014 Updated: 20/05/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

LiveZilla prior to 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which might allow remote malicious users to obtain sensitive information and gain privileges by accessing the loginName and loginPassword variables using an independent cross-site scripting (XSS) attack.

Vulnerable Product Search on Vulmon Subscribe to Product

livezilla livezilla 5.0.1.1

livezilla livezilla

livezilla livezilla 5.0.1.2

livezilla livezilla 5.0.1.0

livezilla livezilla 5.1.1.0

livezilla livezilla 5.1.0.0

livezilla livezilla 5.0.1.4

livezilla livezilla 5.0.1.3

Exploits

LiveZilla version 5120 stores a user's login and password in javascript ...