LiveZilla 'setcookievalue () 'function PHP Object Injection Vulnerability
Release date:
Updated on:
Affected Systems:
LiveZilla GmbH LiveZilla <5.1.2.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 64383
CVE (CAN) ID: CVE-2013-7034
LiveZilla is an online help and online support system.
In LiveZilla 5.1.2.0 and other versions, the setCookieValue function of in _ lib/functions. global. inc. php has the Remote PHP Object injection vulnerability in implementation. Attackers can inject existing object instances by using the controllable livezilla cookie (livezilla cookie is a base64-encoded serialized php object. The successful exploitation of this vulnerability may allow attackers to delete files or perform cross-site scripting attacks.
<* Source: Jakub Zoczek
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
LiveZilla GmbH
--------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://forums.livezilla.net/index.php? /Topic/163-livezilla-changelog/
Reference: http://xforce.iss.net/xforce/xfdb/89796
This article permanently updates the link address: