看板 Bugtraq 關於我們 聯絡資訊
duminic=C4=83, 15 decembrie 2013, 01:51:02 UTC+2, zoc...@gmail.com a scris: > Author: Jakub Zoczek [zoczus@gmail.com] >=20 > CVE Reference: CVE-2013-7034 >=20 > Product: LiveZilla=20 >=20 > Vendor: LiveZilla GmbH [http://livezilla.net] >=20 > Affected version: 5.1.2.0 >=20 > Severity: Medium >=20 > CVSSv2 Score: 6.4 (AV:N/AC:L/Au:N/C:P/I:P/A:N) >=20 > Status: Fixed >=20 >=20 >=20 > 0x01 Background >=20 >=20 >=20 > LiveZilla, the widely-used and trusted Live Help and Live Support System. >=20 >=20 >=20 > 0x02 Description >=20 >=20 >=20 > LiveZilla in version 5.1.2.0 is prone to remote PHP Object Injection. Att= acker is able to inject existing class instances using user-controled livez= illa cookie which is simply base64 encoded, serialized php object. This may= end with unspecified behavior of application, depends on context.=20 >=20 >=20 >=20 > Vulnerable file: _lib/functions.global.inc.php , function: setCookieValue= () >=20 >=20 >=20 > 0x03 Proof of Concept >=20 >=20 >=20 > Won't provide. >=20 >=20 >=20 > 0x04 Fix >=20 >=20 >=20 > Vulnerability was fixed in LiveZilla 5.1.2.1 version. >=20 >=20 >=20 > 0x05 Timeline >=20 >=20 >=20 > 08.12.2013 - Vendor notified >=20 > 09.12.2013 - Vendor responded with informations about planned release=20 >=20 > 10.12.2013 - Version 5.1.2.1 released >=20 > 15.12.2013 - Public Disclosure Hello do u have a POC ? Can you posting the vulnerabilty exacting ? Thanks= =20