« Volver al listado

CVE-2013-6223

Estado: ModificadaBaja (2.1)—

LiveZilla anterior a 5.1.1.0 almacena el nombre de usuario y contraseña de administración codificados en Base64 en un fichero 1click, lo que permite a usuarios locales obtener acceso mediante la lectura del fichero.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-6223",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-06-09T19:55:10.240",
  "references": [
    {
      "url": "http://blog.curesec.com/article/blog/27.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://forums.livezilla.net/index.php?/topic/163-livezilla-changelog/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/100400",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2013/Nov/210",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://blog.curesec.com/article/blog/27.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://forums.livezilla.net/index.php?/topic/163-livezilla-changelog/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/100400",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2013/Nov/210",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-255"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local users to obtain access by reading the file."
    },
    {
      "lang": "es",
      "value": "LiveZilla anterior a 5.1.1.0 almacena el nombre de usuario y contraseña de administración codificados en Base64 en un fichero 1click, lo que permite a usuarios locales obtener acceso mediante la lectura del fichero."
    }
  ],
  "lastModified": "2026-06-17T00:00:10.957",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E71FD11-CCE4-4D64-B16A-87527E8076B9",
              "versionEndIncluding": "5.1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:3.1.8.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56789521-4DD0-4FE8-80E4-9D99BDD43551"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:3.2.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8284B387-D399-49D1-921C-414A8B9E6DF6"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:4.0.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D97BE25-92A1-4F57-B433-0650BEC6A714"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:4.0.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D38AA0A9-D234-4366-BCA2-7E8D44B5AE3C"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:4.0.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE5118FB-A7DB-4E40-8B65-F72BA94FADF6"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:4.1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C3585416-E7D6-4F2E-974F-6033B1EA493D"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:4.1.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A015EC43-FEE9-401E-879E-5075E98E7566"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:4.2.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "171BA61E-BC9A-46E7-B69A-CDC01D6B1CC7"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:4.2.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "013B3FB8-47DB-4C27-894E-E837200D267F"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:5.0.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4F8D1A5-B008-4D92-9522-FD9B82A5C6F3"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:5.0.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C198E0EB-5E32-4952-9297-BC05C2E8EC77"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:5.0.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E252F349-6B4C-4DD0-B566-6F701F5D639F"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:5.0.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF76D3A5-3926-40B2-85A2-DF088428CB9C"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:5.0.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BF03B88-78BB-447E-A8E3-3053DEAB5BA9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}