what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

LiveZilla 5.1.1.0 Cross Site Scripting

LiveZilla 5.1.1.0 Cross Site Scripting
Posted Dec 10, 2013
Authored by Jakub Zoczek

LiveZilla version 5.1.1.0 suffers from multiple stored cross site scripting issues in the web-based Operator Client and LiveZilla client.

tags | exploit, web, xss
advisories | CVE-2013-7003
SHA-256 | a9a6519e8b5a96c47677b39baf14e1fa3cb06fc3188411397cdaecebcc214f3f

LiveZilla 5.1.1.0 Cross Site Scripting

Change Mirror Download
Author: Jakub Zoczek [zoczus@gmail.com]
CVE Reference: CVE-2013-7003
Product: LiveZilla
Vendor: LiveZilla GmbH [http://livezilla.net]
Affected version: 5.1.1.0
Severity: Medium
CVSSv2 Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Status: Fixed


0x01 Background

LiveZilla, the widely-used and trusted Live Help and Live Support System.

0x02 Description

LiveZilla in version 5.1.1.0 is prone to multiple Stored Cross-Site Scripting issues in Webbased Operator Client and LiveZilla Client. Attacker can put payloads in fields like "full name" , "company", or create crafted filename to exploit this vulnerability.

0x03 Proof of Concepts

Name and Surname variant:

My name is Jakub and this is looong username <img src="a" onerror="alert(document.cookie)">h

Operator who will try to chat with attacker with this name will get javascript code executed.

Screenshots:

http://postimg.org/image/orvwl36on/
http://postimg.org/image/uhh72ij6f/
http://postimg.org/image/6f0d7n2jb/
http://postimg.org/image/6hk8uh66v/
http://postimg.org/image/7z5p61axj/

Uploaded filename variant:

If attacker (while chatting) will try to upload specially crafted file with name: c"><img src="a" onerror="alert(document.cookie)">hh.jpg - then operator would get javascript code execution without any interaction.

Screenshots:

http://postimg.org/image/kp9xj4ivr/
http://postimg.org/image/pqhbkhqc7/
http://postimg.org/image/7c6sgie1j/

0x04 Fix

Vulnerabilities was fixed in LiveZilla 5.1.2.0 version.

0x05 Timeline

21.11.2013 - Vendor notified
01.12.2013 - Ping
02.12.2013 - Vendor responded with information about planing fix
06.12.2013 - Fixed version released
10.12.2013 - Public Disclosure
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    0 Files
  • 6
    Aug 6th
    0 Files
  • 7
    Aug 7th
    0 Files
  • 8
    Aug 8th
    0 Files
  • 9
    Aug 9th
    0 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close