VulnerabilityModified
CVE-2013-7003
Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) full name field, (2) company field, or (3) filename to chat.php.
MEDIUM 4.3EPSS 1.85%
Does this matter?
Lower severity and a low EPSS score (1.85%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) full name field, (2) company field, or (3) filename to chat.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.85% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- livezilla/livezilla
- Source
- cve@mitre.org
References
- http://osvdb.org/100828
- http://packetstormsecurity.com/files/124374/LiveZilla-5.1.1.0-Cross-Site-Scripting.htmlExploit
- http://seclists.org/bugtraq/2013/Dec/42
- http://www.securityfocus.com/bid/64202
- http://osvdb.org/100828
- http://packetstormsecurity.com/files/124374/LiveZilla-5.1.1.0-Cross-Site-Scripting.htmlExploit
- http://seclists.org/bugtraq/2013/Dec/42
- http://www.securityfocus.com/bid/64202
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.