Kacper SzurekTagsPolishNewsletterAbout
YouTubeWebinaryFacebookTwitter
Kacper Szurek
TagsPolishNewsletterAboutYouTubeWebinaryFacebookTwitter
LiveZilla 5.3.0.8 XSS

30-03-2015 / Vulnerabilities

LiveZilla 5.3.0.8 XSS

Spis treści

  1. Proof of Concept
  2. Timeline

Name field (name="form_111") in chat.php may be used to send XSS visible inside Webbased Operator Client.

Proof of Concept

Put XSS inside Name field in chat.php for example:

<script>alert("XSS");</script>

XSS will be visible for operator whose uses Webbased Operator Client and accept your chat and receive at least two messages from you.

Timeline

  • 25-11-2014: Discovered
  • 25-11-2014: Vendor notified
  • 15-01-2015: Version 5.4.0.0 released, issue resolved

Vulnerabilities

Kallithea <= 0.3.4 Incorrect access control and XSS

This vulnerability allows a normal user to modify the permissions of repositories that he normally shouldn’t have access to.

12-12-2018

2 MIN READ

Gitea 1.4.0 Unauthenticated Remote Code Execution

Vulnerabilities

Gitea 1.4.0 Unauthenticated Remote Code Execution

This is part 1 of 3 about bugs inside Gitea

05-07-2018

5 MIN READ

Vulnerabilities

ManageEngine Exchange Reporter Plus Unauthenticated Remote Code Execution

How to create a Metasploit module in example?

28-06-2018

1 MIN READ

© 2026 Kacper Szurek
Disclosure Policy
YouTube
Facebook
Twitter