| OSVDB ID | Disclosure Date | Title |
|
75334
Description:
W-Agora contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'bn' parameter upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-16
|
W-Agora index.php bn Parameter XSS
|
|
31669
Description:
(Description Provided by CVE) : w-agora 4.2.1 allows remote attackers to obtain sensitive information by via the (1) bn[] array parameter to index.php, which expects a string, and (2) certain parameters to delete_forum.php, which displays the path name in the resulting error message.
|
2007-03-19
|
w-Agora index.php bn[] Variable Path Disclosure
|
|
39883
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in w-Agora 4.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.
|
2007-12-30
|
W-Agora index.php cat Parameter SQL Injection
|
|
3173
Description:
W-Agora contains a feature that may lead to an unauthorized information disclosure. The issue is triggered when index.php is requested with "about" or "info" as the query, which will disclose user names, database-systems, paths, and versions resulting in a loss of confidentiality.
|
2003-07-11
|
w-Agora index.php Information Disclosure
|
|
34381
Description:
(Description Provided by CVE) : w-Agora (Web-Agora) allows remote attackers to obtain sensitive information via a request to rss.php with an invalid (1) site or (2) bn parameter, (3) a certain value of the site[] parameter, or (4) an empty value of the bn[] parameter; a request to index.php with a certain value of the (5) site[] or (6) sort[] parameter; (7) a request to profile.php with an empty value of the site[] parameter; or a request to search.php with (8) an empty value of the bn[] parameter or a certain value of the (9) pattern[] or (10) search_date[] parameter, which reveal the path in various error messages, probably related to variable type inconsistencies. NOTE: the bn[] parameter to index.php is already covered by CVE-2007-0606.1.
|
2007-03-20
|
W-Agora index.php Multiple Variable Path Disclosure
|
|
18831
Description:
(Description Provided by CVE) : Directory traversal vulnerability in index.php in W-Agora 4.2.0 and earlier allows remote attackers to read arbitrary files via the site parameter.
|
2005-08-18
|
w-Agora index.php site Parameter Traversal Arbitrary File Access
|
|
11246
Description:
w-Agora contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to index.php3 not properly sanitizing user input supplied to unspecified variables. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2003-12-10
|
w-Agora index.php3 Remote File Inclusion
|
|
28167
Description:
w-Agora contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified variables upon submission to the index.php3 script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-12-10
|
w-Agora index.php3 Unspecified Parameter XSS
|
|
20060
Description:
Unknown / Incomplete
|
2005-10-17
|
w-Agora insert.php Arbitrary File Upload
|
|
27202
Description:
W-Agora contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the insert.php script not properly sanitizing user input before being called by other scripts. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-22
|
w-Agora insert.php Multiple Script Remote File Inclusion
|
|
11245
Description:
w-Agora contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to insert.php3 not properly sanitizing user input supplied to unspecified variables. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2003-12-10
|
w-Agora insert.php3 Remote File Inclusion
|
|
28166
Description:
w-Agora contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified variables upon submission to the insert.php3 script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-12-10
|
w-Agora insert.php3 Unspecified Parameter XSS
|
|
75335
Description:
Unknown / Incomplete
|
2011-03-16
|
W-Agora list.php bn Parameter XSS
|
|
10462
Description:
(Description Provided by CVE) : list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.
|
2004-09-29
|
w-Agora list.php Path Disclosure
|
|
11251
Description:
w-Agora contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user input upon submission to the list.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-10-19
|
w-Agora list.php XSS
|
|
10459
Description:
W-Agora contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate "loginuser" variables upon submission to the login.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-09-29
|
w-Agora login.php loginuser Parameter XSS
|
|
75170
Description:
Unknown / Incomplete
|
2010-10-27
|
W-Agora login.php3 Multiple Parameter XSS
|
|
43834
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default parameter to (1) add_user.php, (2) create_forum.php, (3) create_user.php, (4) delete_notes.php, (5) delete_user.php, (6) edit_forum.php, (7) mail_users.php, (8) moderate_notes.php, and (9) reorder_forums.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-03-20
|
W-Agora mail_users.php bn_dir_default Parameter Remote File Inclusion
|
|
43835
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default parameter to (1) add_user.php, (2) create_forum.php, (3) create_user.php, (4) delete_notes.php, (5) delete_user.php, (6) edit_forum.php, (7) mail_users.php, (8) moderate_notes.php, and (9) reorder_forums.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-03-20
|
W-Agora moderate_notes.php bn_dir_default Parameter Remote File Inclusion
|
|
11236
Description:
w-Agora contains a flaw that may allow a malicious forum moderator to make changes to arbitrary forums. The issue is triggered due to the authentication module not properly validating a moderator's credentials. This may allow a person given specific forum moderation privileges to moderate any forum.
|
2001-03-07
|
w-Agora Moderator Arbitrary Forum Modification
|
|
54099
Description:
W-Agora contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when specially crafted URL request is made with directory transversing "dot dot" sequences to either "index.php3" or "modules.php3" occurs, which will disclose any known file that the web server can access resulting in a loss of confidentiality.
|
2003-01-11
|
w-Agora modules.php file Parameter Traversal Arbitrary File Access
|
|
3172
Description:
W-Agora contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the mod and file variables upon submission to the modules.php3 script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-07-11
|
w-Agora modules.php Path Disclosure
|
|
28168
Description:
w-Agora contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified variables upon submission to the modules.php3 script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-12-10
|
w-Agora modules.php3 Unspecified Parameter XSS
|
|
11247
Description:
w-Agora contains a flaw that may allow a remote attacker to conduct cross site scripting attacks and/or include arbitrary PHP commands or files. The issue is due to the modules.php3 script not properly sanitizing user input allowing for such attacks. No further details have been provided.
|
2003-12-10
|
w-Agora modules.php3 XSS & PHP Inclusion
|
|
11239
Description:
w-Agora contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the scripts in the 'include' and 'user' directories not properly sanitizing user input supplied to the 'inc_dir' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2002-06-08
|
w-Agora Multiple Script inc_dir Parameter Remote File Inclusion
|
|
11242
Description:
w-Agora contains a flaw related to the "where" and "sort" URL arguments, as related to the "before_access" function. No further details have been provided.
|
2002-12-09
|
w-Agora Multiple URL Argument Unspecified Issue
|
|
75171
Description:
W-Agora on Windows contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'for-print.php3' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'bn' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-10-27
|
W-Agora on Windows for-print.php3 bn Parameter Traversal Local File Inclusion
|
|
75172
Description:
W-Agora on Windows contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'login.php3' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'bn' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-10-27
|
W-Agora on Windows login.php3 bn Parameter Traversal Local File Inclusion
|
|
75174
Description:
W-Agora on Windows contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'search.php3' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'bn' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-10-22
|
W-Agora on Windows search.php3 bn Parameter Traversal Local File Inclusion
|
|
34377
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the showuser parameter to profile.php, the (2) search_forum or (3) search_user parameter to search.php, or (4) the userid parameter to change_password.php.
|
2007-03-20
|
W-Agora profile.php showuser Parameter XSS
|