all things security

LiveZilla 5.1.1.0 Cross Site Scripting

LiveZilla 5.1.1.0 Cross Site Scripting
Posted Dec 10, 2013
Authored by Jakub Zoczek

LiveZilla version 5.1.1.0 suffers from multiple stored cross site scripting issues in the web-based Operator Client and LiveZilla client.

tags | exploit, web, xss
advisories | CVE-2013-7003
MD5 | 5946f7231aaa791b6bafb05ea433d45b

LiveZilla 5.1.1.0 Cross Site Scripting

Change Mirror Download
Author: Jakub Zoczek [zoczus@gmail.com]
CVE Reference: CVE-2013-7003
Product: LiveZilla
Vendor: LiveZilla GmbH [http://livezilla.net]
Affected version: 5.1.1.0
Severity: Medium
CVSSv2 Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Status: Fixed


0x01 Background

LiveZilla, the widely-used and trusted Live Help and Live Support System.

0x02 Description

LiveZilla in version 5.1.1.0 is prone to multiple Stored Cross-Site Scripting issues in Webbased Operator Client and LiveZilla Client. Attacker can put payloads in fields like "full name" , "company", or create crafted filename to exploit this vulnerability.

0x03 Proof of Concepts

Name and Surname variant:

My name is Jakub and this is looong username <img src="a" onerror="alert(document.cookie)">h

Operator who will try to chat with attacker with this name will get javascript code executed.

Screenshots:

http://postimg.org/image/orvwl36on/
http://postimg.org/image/uhh72ij6f/
http://postimg.org/image/6f0d7n2jb/
http://postimg.org/image/6hk8uh66v/
http://postimg.org/image/7z5p61axj/

Uploaded filename variant:

If attacker (while chatting) will try to upload specially crafted file with name: c"><img src="a" onerror="alert(document.cookie)">hh.jpg - then operator would get javascript code execution without any interaction.

Screenshots:

http://postimg.org/image/kp9xj4ivr/
http://postimg.org/image/pqhbkhqc7/
http://postimg.org/image/7c6sgie1j/

0x04 Fix

Vulnerabilities was fixed in LiveZilla 5.1.2.0 version.

0x05 Timeline

21.11.2013 - Vendor notified
01.12.2013 - Ping
02.12.2013 - Vendor responded with information about planing fix
06.12.2013 - Fixed version released
10.12.2013 - Public Disclosure

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

July 2017

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    2 Files
  • 2
    Jul 2nd
    3 Files
  • 3
    Jul 3rd
    15 Files
  • 4
    Jul 4th
    4 Files
  • 5
    Jul 5th
    15 Files
  • 6
    Jul 6th
    15 Files
  • 7
    Jul 7th
    10 Files
  • 8
    Jul 8th
    2 Files
  • 9
    Jul 9th
    10 Files
  • 10
    Jul 10th
    15 Files
  • 11
    Jul 11th
    15 Files
  • 12
    Jul 12th
    19 Files
  • 13
    Jul 13th
    16 Files
  • 14
    Jul 14th
    15 Files
  • 15
    Jul 15th
    3 Files
  • 16
    Jul 16th
    2 Files
  • 17
    Jul 17th
    8 Files
  • 18
    Jul 18th
    11 Files
  • 19
    Jul 19th
    15 Files
  • 20
    Jul 20th
    15 Files
  • 21
    Jul 21st
    15 Files
  • 22
    Jul 22nd
    7 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2016 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close