![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.803785 |
Category: | Web application abuses |
Title: | LiveZilla 'g_language' Parameter Cross Site Scripting Vulnerability |
Summary: | LiveZilla is prone to a cross-site scripting (XSS) vulnerability. |
Description: | Summary: LiveZilla is prone to a cross-site scripting (XSS) vulnerability. Vulnerability Insight: - The flaw is due to input passed via the 'g_language' GET parameter to '/mobile/php/translation/index.php' is not properly sanitised before being returned to the user. - Input passed via the username and message body to chat.php when starting a new chat session is not properly sanitised before being used. Vulnerability Impact: Successful exploitation will allow remote attackers to execute arbitrary HTML and script code in a users browser session in the context of an affected site and launch other attacks. Affected Software/OS: LiveZilla version 5.1.0.0 Solution: Upgrade to LiveZilla 5.1.1.0 or later. CVSS Score: 4.3 CVSS Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2013-7002 Bugtraq: 20131208 LiveZilla 5.1.0.0 Reflected XSS in translations (Google Search) http://archives.neohapsis.com/archives/bugtraq/2013-12/0032.html http://packetstormsecurity.com/files/124344 http://ropchain.org/advisories/CVE-2013-7002.txt http://secunia.com/advisories/54505 XForce ISS Database: livezilla-cve20137002-xss(89525) https://exchange.xforce.ibmcloud.com/vulnerabilities/89525 Common Vulnerability Exposure (CVE) ID: CVE-2013-6224 http://seclists.org/fulldisclosure/2013/Nov/208 http://packetstormsecurity.com/files/124222 http://www.livezilla.net/board/index.php?/topic/163-livezilla-changelog/ https://cureblog.de/2013/12/cve-2013-6224-cross-site-scripting-in-livezilla http://osvdb.org/100399 http://osvdb.org/100401 http://osvdb.org/100402 XForce ISS Database: livezilla-cve20136224-xss(89315) https://exchange.xforce.ibmcloud.com/vulnerabilities/89315 |
Copyright | Copyright (C) 2013 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |