LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local users to obtain access by reading the file.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://forums.livezilla.net/index.php?/topic/163-livezilla-changelog/ | vendor advisory |
http://blog.curesec.com/article/blog/27.html | exploit |
http://osvdb.org/100400 | vdb entry |
http://seclists.org/fulldisclosure/2013/Nov/210 | mailing list |