Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · net nu 117 bronnen 1 kritiek 6 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2013-7033

MEDIUM · 4.3 CVSS Gepubliceerd: CWE-310

Beschrijving

LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which might allow remote attackers to obtain sensitive information and gain privileges by accessing the loginName and loginPassword variables using an independent cross-site scripting (XSS) attack.

Vendors

Livezilla

Affected products

Livezilla

References