W-Agora Inc_Dir Multiple Remote File Include Vulnerabilities
BID:18601
Info
W-Agora Inc_Dir Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 18601 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2006 12:00AM |
| Updated: | Jun 23 2006 03:35AM |
| Credit: | Dedi Dwianto a.k.a the_day is credited with discovering this vulnerability. |
| Vulnerable: |
W-Agora W-Agora 4.2 |
| Not Vulnerable: | |
Discussion
W-Agora Inc_Dir Multiple Remote File Include Vulnerabilities
W-Agora is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input to the application.
An attacker may leverage these issues to include arbitrary remote PHP files containing malicious script code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system. Other attacks are also possible.
W-Agora is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input to the application.
An attacker may leverage these issues to include arbitrary remote PHP files containing malicious script code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system. Other attacks are also possible.
Exploit / POC
W-Agora Inc_Dir Multiple Remote File Include Vulnerabilities
These vulnerabilities can be exploited using a web browser.
These vulnerabilities can be exploited using a web browser.
Solution / Fix
W-Agora Inc_Dir Multiple Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please email us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please email us at: [email protected]:[email protected].
References
W-Agora Inc_Dir Multiple Remote File Include Vulnerabilities
References:
References:
- W-Agora Homepage (W-Agora)
- W-Agora Remote File Include Vuln. (Dedi Dwianto)
- [ECHO_ADV_34$2006] W-Agora (Web-Agora) <= 4.2.0 (Defi Dwianto )