« Volver al listado

CVE-2013-7033

Estado: ModificadaMedia (4.3)—

LiveZilla anterior a 5.1.2.1 incluye la contraseña del operador en texto plano en código Javascript que está generado por lz/mobile/chat.php, lo que podría permitir a atacantes remotos obtener información sensible y ganar privilegios mediante el acceso a las variables loginName y loginPassword utilizando un ataque de XSS independiente.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-7033",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-05-19T14:55:09.923",
  "references": [
    {
      "url": "http://forums.livezilla.net/index.php?/topic/163-livezilla-changelog/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://packetstormsecurity.com/files/124444/LiveZilla-5.1.2.0-Insecure-Password-Storage.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://forums.livezilla.net/index.php?/topic/163-livezilla-changelog/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.com/files/124444/LiveZilla-5.1.2.0-Insecure-Password-Storage.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which might allow remote attackers to obtain sensitive information and gain privileges by accessing the loginName and loginPassword variables using an independent cross-site scripting (XSS) attack."
    },
    {
      "lang": "es",
      "value": "LiveZilla anterior a 5.1.2.1 incluye la contraseña del operador en texto plano en código Javascript que está generado por lz/mobile/chat.php, lo que podría permitir a atacantes remotos obtener información sensible y ganar privilegios mediante el acceso a las variables loginName y loginPassword utilizando un ataque de XSS independiente."
    }
  ],
  "lastModified": "2026-06-17T00:01:19.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8685C528-1012-467B-9011-C668ABFF4FF1",
              "versionEndIncluding": "5.1.2.0"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:5.0.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4F8D1A5-B008-4D92-9522-FD9B82A5C6F3"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:5.0.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C198E0EB-5E32-4952-9297-BC05C2E8EC77"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:5.0.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E252F349-6B4C-4DD0-B566-6F701F5D639F"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:5.0.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF76D3A5-3926-40B2-85A2-DF088428CB9C"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:5.0.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BF03B88-78BB-447E-A8E3-3053DEAB5BA9"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:5.1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5857ABFC-FA81-4D0B-9CF1-EE64422A4B96"
            },
            {
              "criteria": "cpe:2.3:a:livezilla:livezilla:5.1.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26D87246-BC8B-4B74-8565-232422517E93"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}