Home page logo

bugtraq logo Bugtraq mailing list archives

LiveZilla Stored XSS in operator clients
From: zoczus () gmail com
Date: Tue, 10 Dec 2013 15:32:12 GMT

Author: Jakub Zoczek [zoczus () gmail com]
CVE Reference: CVE-2013-7003
Product: LiveZilla 
Vendor: LiveZilla GmbH [http://livezilla.net]
Affected version:
Severity: Medium
CVSSv2 Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Status: Fixed

0x01 Background

LiveZilla, the widely-used and trusted Live Help and Live Support System.

0x02 Description

LiveZilla in version is prone to multiple Stored Cross-Site Scripting issues in Webbased Operator Client and 
LiveZilla Client. Attacker can put payloads in fields like "full name" , "company", or create crafted filename to 
exploit this vulnerability.

0x03 Proof of Concepts

Name and Surname variant: 

My name is Jakub and this is looong username <img src="a" onerror="alert(document.cookie)">h

Operator who will try to chat with attacker with this name will get javascript code executed.



Uploaded filename variant: 

If attacker (while chatting) will try to upload specially crafted file with name: c"><img src="a" 
onerror="alert(document.cookie)">hh.jpg - then operator would get javascript code execution without any interaction.


0x04 Fix

Vulnerabilities was fixed in LiveZilla version.

0x05 Timeline

21.11.2013 - Vendor notified
01.12.2013 - Ping
02.12.2013 - Vendor responded with information about planing fix 
06.12.2013 - Fixed version released
10.12.2013 - Public Disclosure

  By Date           By Thread  

Current thread:
  • LiveZilla Stored XSS in operator clients zoczus (Dec 10)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]