Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2013-7034

HIGH · 7.5 CVSS Gepubliceerd: CWE-94

Beschrijving NL

Met de setCookieValue-functie in _lib/functions.global.inc.php in LiveZilla vóór 5.1.2.1 kunnen externe aanvallers willekeurige PHP-code uitvoeren via een geserialiseerd PHP-object in een cookie.

Origineel (Engels) tonen

The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP code via a serialized PHP object in a cookie.

Vendors

Livezilla

Affected products

Livezilla

References