Skip to main content

Vendor/product archive

livezilla / livezilla CVEs

Beta · best-effort

21 CVEs tagged to livezilla / livezilla4 Critical, 2 High, 14 Medium, 1 Low, 0 Unrated.

CVE-2020-9758

Published Mar 9, 2020

An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the name parameter. Triggering this can fetch the username and…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12963

Published Jun 25, 2019

LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12962

Published Jun 25, 2019

LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12960

Published Jun 25, 2019

LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12940

Published Jun 24, 2019

LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of the depth parameter.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12939

Published Jun 24, 2019

LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-10810

Published May 16, 2018

chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15869

Published Jan 18, 2018

Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web script or HTML via the search-for paramet…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6223

Published Jun 9, 2014

LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local users to obtain access by reading the file.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-7385

Published May 19, 2014

LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which allows remote attackers…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7033

Published May 19, 2014

LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which might allow remote attackers to obtain sensi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7034

Published May 5, 2014

The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP code via a serialized PHP object in a coo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7003

Published May 5, 2014

Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) full name field, (2) comp…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7032

Published Feb 14, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7002

Published Dec 21, 2013

Cross-site scripting (XSS) vulnerability in mobile/php/translation/index.php in LiveZilla before 5.1.1.0 allows remote attackers to inject arbitrary web script or HTML via the g_l…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6224

Published Dec 10, 2013

Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) a name in the call administra…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4276

Published Dec 30, 2010

Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allows remote attackers to inject arbitrary w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4450

Published Dec 29, 2009

Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) lat, (2) lng, and (3)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1