CVE-2017-15869

Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web script or HTML via the search-for parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:livezilla:livezilla:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:15

Type Values Removed Values Added
References () http://www.securityfocus.com/archive/1/541688/100/0/threaded - Exploit, Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/541688/100/0/threaded - Exploit, Third Party Advisory, VDB Entry
References () https://www.livezilla.net/changelog/en/ - Release Notes, Vendor Advisory () https://www.livezilla.net/changelog/en/ - Release Notes, Vendor Advisory
References () https://www.pallas.com/advisories/cve-2017-15869-livezilla-xss-knowledgebase - Exploit, Third Party Advisory () https://www.pallas.com/advisories/cve-2017-15869-livezilla-xss-knowledgebase - Exploit, Third Party Advisory

Information

Published : 2018-01-18 14:29

Updated : 2024-11-21 03:15


NVD link : CVE-2017-15869

Mitre link : CVE-2017-15869

CVE.ORG link : CVE-2017-15869


JSON object : View

Products Affected

livezilla

  • livezilla
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')