| OSVDB ID | Disclosure Date | Title |
|
43828
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default parameter to (1) add_user.php, (2) create_forum.php, (3) create_user.php, (4) delete_notes.php, (5) delete_user.php, (6) edit_forum.php, (7) mail_users.php, (8) moderate_notes.php, and (9) reorder_forums.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-03-20
|
W-Agora add_user.php bn_dir_default Parameter Remote File Inclusion
|
|
11237
Description:
w-Agora contains a flaw related to the "no_auth" variable in the admin.php3 script. No further details have been provided.
|
2001-03-07
|
w-Agora admin.php3 no_auth Variable Unspecified Issue
|
|
3174
Description:
W-Agora contains a flaw that may allow a malicious user to arbitrarily upload files. The issue is triggered when only if the forum's notes directory hasn't been restricted as recommended by W-Agora. It is possible that the flaw may allow index.php3 to be tricked into executing the uploaded files resulting in a loss of confidentiality, integrity, or availability.
|
2003-07-11
|
w-Agora Arbitrary File Upload and Execution Flaw
|
|
11250
Description:
w-Agora contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user input upon submission to the auth.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-10-19
|
w-Agora auth.php XSS
|
|
11248
Description:
w-Agora contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to auth.php3 not properly sanitizing user input supplied to unspecified variables. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2003-12-10
|
w-Agora auth.php3 Remote File Inclusion
|
|
28169
Description:
w-Agora contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified variables upon submission to the auth.php3 script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-12-10
|
w-Agora auth.php3 Unspecified Parameter XSS
|
|
11243
Description:
w-Agora contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to browse.php3 not properly sanitizing user input supplied to unspecified variables. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2003-12-10
|
w-Agora browse.php3 Remote File Inclusion
|
|
28170
Description:
w-Agora contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified variables upon submission to the browse.php3 script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-12-10
|
w-Agora browse.php3 Unspecified Parameter XSS
|
|
20059
Description:
Unknown / Incomplete
|
2005-10-17
|
w-Agora browse_avatar.php Arbitrary File Upload
|
|
34384
Description:
(Description Provided by CVE) : Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a forum message with an attached file, which is stored under forums/hello/hello/notes/ or (2) by using browse_avatar.php to upload a file with a double extension, as demonstrated by .php.jpg.
|
2007-03-20
|
W-Agora browse_avatar.php Multiple File Extension Upload Arbitrary Code Execution
|
|
34379
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the showuser parameter to profile.php, the (2) search_forum or (3) search_user parameter to search.php, or (4) the userid parameter to change_password.php.
|
2007-03-20
|
W-Agora change_password.php userid Parameter XSS
|
|
43829
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default parameter to (1) add_user.php, (2) create_forum.php, (3) create_user.php, (4) delete_notes.php, (5) delete_user.php, (6) edit_forum.php, (7) mail_users.php, (8) moderate_notes.php, and (9) reorder_forums.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-03-20
|
W-Agora create_forum.php bn_dir_default Parameter Remote File Inclusion
|
|
43830
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default parameter to (1) add_user.php, (2) create_forum.php, (3) create_user.php, (4) delete_notes.php, (5) delete_user.php, (6) edit_forum.php, (7) mail_users.php, (8) moderate_notes.php, and (9) reorder_forums.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-03-20
|
W-Agora create_user.php bn_dir_default Parameter Remote File Inclusion
|
|
31668
Description:
w-Agora contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a specially-crafted URL request with an invalid parameter is passed to delete_forum.php, leading to a fatal error due to a call to an undefined function msgform() in delete_forum.php. The error information discloses the true path of the server-side scripts, resulting in a loss of confidentiality.
|
2007-03-19
|
w-Agora delete_forum.php Path Disclosure
|
|
43831
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default parameter to (1) add_user.php, (2) create_forum.php, (3) create_user.php, (4) delete_notes.php, (5) delete_user.php, (6) edit_forum.php, (7) mail_users.php, (8) moderate_notes.php, and (9) reorder_forums.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-03-20
|
W-Agora delete_notes.php bn_dir_default Parameter Remote File Inclusion
|
|
43832
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default parameter to (1) add_user.php, (2) create_forum.php, (3) create_user.php, (4) delete_notes.php, (5) delete_user.php, (6) edit_forum.php, (7) mail_users.php, (8) moderate_notes.php, and (9) reorder_forums.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-03-20
|
W-Agora delete_user.php bn_dir_default Parameter Remote File Inclusion
|
|
10458
Description:
W-Agora contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate "thread" variables upon submission to the "download_thread.php" script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-09-29
|
w-Agora download_thread.php thread Parameter XSS
|
|
43833
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default parameter to (1) add_user.php, (2) create_forum.php, (3) create_user.php, (4) delete_notes.php, (5) delete_user.php, (6) edit_forum.php, (7) mail_users.php, (8) moderate_notes.php, and (9) reorder_forums.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-03-20
|
W-Agora edit_forum.php bn_dir_default Parameter Remote File Inclusion
|
|
38025
Description:
(Description Provided by CVE) : Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary form field name containing the script, which is echoed back to the user when displaying the form.
|
2002-12-19
|
w-Agora editform.php Arbitrary Form Field XSS
|
|
3169
Description:
W-Agora contains a flaw that may allow an "admin" or "root" user to include php files. The issue is triggered when a specially crafted URL request to ediform.php3 occurs. It is possible that the flaw may allow execution of arbitrary code resulting in a loss of confidentiality, integrity, and/or availability.
|
2002-12-19
|
w-Agora editform.php file Variable Arbitrary Local PHP Code Execution
|
|
20058
Description:
Unknown / Incomplete
|
2005-10-14
|
w-Agora extras/quicklist.php Remote Command Execution
|
|
75169
Description:
Unknown / Incomplete
|
2010-10-27
|
W-Agora for-print.php3 Multiple Parameter XSS
|
|
10460
Description:
w-Agora contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'userid' variables upon submission to the 'forgot_password.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-09-30
|
w-Agora forgot_password.php userid Parameter XSS
|
|
34383
Description:
(Description Provided by CVE) : Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a forum message with an attached file, which is stored under forums/hello/hello/notes/ or (2) by using browse_avatar.php to upload a file with a double extension, as demonstrated by .php.jpg.
|
2007-03-20
|
W-Agora Forum Message Attachment Unrestricted File Upload
|
|
87220
Description:
w-Agora contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the getfile.php script not properly sanitizing user-supplied input to the 'att_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-08-17
|
w-Agora getfile.php att_id Parameter SQL Injection
|
|
87219
Description:
w-Agora contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'att_id' parameter upon submission to the getfile.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-08-17
|
w-Agora getfile.php att_id Parameter XSS
|
|
75333
Description:
Unknown / Incomplete
|
2011-03-16
|
W-Agora getfile.php Unspecified Parameter XSS
|
|
31670
Description:
w-Agora contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker appends "/globals.inc" to the end of a request, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2007-03-19
|
w-Agora globals.inc Direct Request Path Disclosure
|
|
25295
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in w-Agora (aka Web-Agora) 4.2.0 allows remote attackers to inject arbitrary web script or HTML via a post with a BBCode tag that contains a JavaScript event name followed by whitespace before the '=' (equals) character, which bypasses a restrictive regular expression that attempts to remove onmouseover and other events.
|
2006-04-29
|
w-Agora HTML/Script Filter Bypass XSS
|
|
11249
Description:
w-Agora contains a flaw that may allow a remote attacker to access normally protected scripts. The issue is due to the default .htaccess file only restricting GET requests. This could allow an attacker to request and interact with scripts using the POST method.
|
2003-12-10
|
w-Agora HTTP POST Request .htaccess Bypass
|