6.8
CVSSv2

CVE-2013-7385

Published: 19/05/2014 Updated: 20/05/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

LiveZilla 5.1.2.1 and previous versions includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which allows remote malicious users to obtain sensitive information and gain privileges by accessing the loginName and loginPassword variables using an independent cross-site scripting (XSS) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7033.

Vulnerable Product Search on Vulmon Subscribe to Product

livezilla livezilla 5.1.2.0

livezilla livezilla 5.0.1.2

livezilla livezilla 5.0.1.0

livezilla livezilla

livezilla livezilla 5.0.1.3

livezilla livezilla 5.0.1.1

livezilla livezilla 5.1.1.0

livezilla livezilla 5.1.0.0

livezilla livezilla 5.0.1.4