← Back

CVE-2013-7385

nvd nist
Published: May 19, 2014Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which allows remote attackers to obtain sensitive information and gain privileges by accessing the loginName and loginPassword variables using an independent cross-site scripting (XSS) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7033.

Affected (9)

Products: Livezilla: Livezilla
1 product
Livezilla
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Livezilla
Up to 5.1.2.1
Version 5.0.1.0
Version 5.0.1.1
Version 5.0.1.2
Version 5.0.1.3
Version 5.0.1.4
Version 5.1.0.0
Version 5.1.1.0
Version 5.1.2.0

Related CWEs

Timeline

No history available yet.