Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Livezilla CRITICAL 9.6
CVE-2020-9758

An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the name parameter. Triggering th…

Fix: 8.0.1.3+
Fix from $2,300 2020-03-09
Livezilla CRITICAL 9.8
CVE-2013-6225EPSS 27%

LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability

No fix yet
Fix from $2,300 2020-01-13
Livezilla CRITICAL 9.8
CVE-2019-12960

LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.

Fix: 8.0.1.1+
Fix from $2,300 2019-06-25
Livezilla HIGH 8.8
CVE-2019-12961

LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.

Fix: 8.0.1.1+
Fix from $1,950 2019-06-25
Livezilla MEDIUM 6.1
CVE-2019-12962EPSS 9%

LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.

Fix: 8.0.1.1+
Fix from $1,600 2019-06-25
Livezilla MEDIUM 6.1
CVE-2019-12963

LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.

Fix: 8.0.1.1+
Fix from $1,600 2019-06-25
Livezilla MEDIUM 6.1
CVE-2019-12964

LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject.

Fix: 8.0.1.1+
Fix from $1,600 2019-06-25
Livezilla CRITICAL 9.8
CVE-2019-12939

LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.

Fix: 8.0.1.1+
Fix from $2,300 2019-06-24
Livezilla MEDIUM 5.9
CVE-2019-12940

LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of the depth p…

Fix: 8.0.1.1+
Fix from $1,600 2019-06-24
Livezilla MEDIUM 6.1
CVE-2018-10810

chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.

Fix: after 7.0.9.5
Fix from $1,600 2018-05-16
Livezilla MEDIUM 6.1
CVE-2017-15869

Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web script or H…

Fix: 7.0.8.9+
Fix from $1,600 2018-01-18
Livezilla MEDIUM 6.8
CVE-2013-7385

LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php,…

Fix: after 5.1.2.1
Fix from $1,600 2014-05-19
Livezilla HIGH 7.5
CVE-2013-7034

The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP code via a …

Fix: after 5.1.2.0
Fix from $1,950 2014-05-05