W-Agora Unauthorized Forum Moderation Access Vulnerability
BID:14150
Info
W-Agora Unauthorized Forum Moderation Access Vulnerability
| Bugtraq ID: | 14150 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2001 12:00AM |
| Updated: | Mar 07 2001 12:00AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
W-Agora W-Agora 4.0.1 |
| Not Vulnerable: |
W-Agora W-Agora 4.0.2 |
Discussion
W-Agora Unauthorized Forum Moderation Access Vulnerability
W-Agora has a flaw in its authentication module which will allow a malicious moderator to bypass the authentication mechanism.
This malicious user may then gain moderation access over other forums that they do not normally moderate.
This issue is reported to exist in W-Agora 4.0.1. Earlier versions may also be affected.
W-Agora has a flaw in its authentication module which will allow a malicious moderator to bypass the authentication mechanism.
This malicious user may then gain moderation access over other forums that they do not normally moderate.
This issue is reported to exist in W-Agora 4.0.1. Earlier versions may also be affected.
Exploit / POC
W-Agora Unauthorized Forum Moderation Access Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
W-Agora Unauthorized Forum Moderation Access Vulnerability
Solution:
This issue has been addressed in version 4.0.2 or higher.
W-Agora W-Agora 4.0.1
Solution:
This issue has been addressed in version 4.0.2 or higher.
W-Agora W-Agora 4.0.1
-
W-Agora w-agora-4.0.2.tar.gz
http://prdownloads.sourceforge.net/w-agora/w-agora-4.0.2.tar.gz?downlo ad