CVE-2013-7034

EUVD-2013-6835
The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP code via a serialized PHP object in a cookie.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
Affected Products (NVD)
VendorProductVersion
livezillalivezilla
𝑥
≤ 5.1.2.0
livezillalivezilla
3.1.8.3
livezillalivezilla
3.2.0.2
livezillalivezilla
4.0.1.0
livezillalivezilla
4.0.1.1
livezillalivezilla
4.0.1.2
livezillalivezilla
4.1.0.3
livezillalivezilla
4.1.0.4
livezillalivezilla
4.2.0.4
livezillalivezilla
4.2.0.5
livezillalivezilla
5.0.1.0
livezillalivezilla
5.0.1.1
livezillalivezilla
5.0.1.2
livezillalivezilla
5.0.1.3
livezillalivezilla
5.0.1.4
livezillalivezilla
5.1.0.0
livezillalivezilla
5.1.1.0
𝑥
= Vulnerable software versions