Agora.CGI Debug Mode Cross-Site Scripting Vulnerability

BID:3702

Info

Agora.CGI Debug Mode Cross-Site Scripting Vulnerability

Bugtraq ID: 3702
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Dec 17 2001 12:00AM
Updated: Dec 17 2001 12:00AM
Credit: This vulnerability was submitted to BugTraq on December 17th, 2001 by "Tamer Sahin" <[email protected]>.
Vulnerable: Agora.cgi Agora.cgi 4.0 d
Agora.cgi Agora.cgi 4.0 c
Agora.cgi Agora.cgi 4.0 b
Agora.cgi Agora.cgi 4.0 a
Agora.cgi Agora.cgi 4.0
Agora.cgi Agora.cgi 3.3 j
Agora.cgi Agora.cgi 3.3 i
Agora.cgi Agora.cgi 3.3 f
Agora.cgi Agora.cgi 3.3 e
Agora.cgi Agora.cgi 3.3 d
Agora.cgi Agora.cgi 3.3 c
Agora.cgi Agora.cgi 3.3 b
Agora.cgi Agora.cgi 3.3 a
Agora.cgi Agora.cgi 3.2 r
Agora.cgi Agora.cgi 3.2 q
Agora.cgi Agora.cgi 3.2 p
Agora.cgi Agora.cgi 3.2 n
Agora.cgi Agora.cgi 3.2 m
Agora.cgi Agora.cgi 3.2 l
Agora.cgi Agora.cgi 3.2 k
Agora.cgi Agora.cgi 3.2 ja
Agora.cgi Agora.cgi 3.2 j
Agora.cgi Agora.cgi 3.2 i
Agora.cgi Agora.cgi 3.2 h
Agora.cgi Agora.cgi 3.2 g
Agora.cgi Agora.cgi 3.2 f
Agora.cgi Agora.cgi 3.2 e
Agora.cgi Agora.cgi 3.2 d
Agora.cgi Agora.cgi 3.2 c
Agora.cgi Agora.cgi 3.2 b
Agora.cgi Agora.cgi 3.2 a
Agora.cgi Agora.cgi 3.2
Not Vulnerable: Agora.cgi Agora.cgi 4.0 e

Discussion

Agora.CGI Debug Mode Cross-Site Scripting Vulnerability

Agora.cgi is a freely available, open source shopping cart system.

When debug mode is enabled, the Agora.cgi script does not adequately filter HTML tags when debug information is being output. Debug mode is not enabled by default and must be explicitly turned on by an administrator.

As a result, it is possible for an attacker to construct a link to the script that includes maliciously constructed script code. When the link is clicked by a web user, the script code will be executed by the client in the context of the site running Agora.cgi.

This issue may be exploited to by an attacker to steal cookie-based authentication credentials, permitting the attacker to hijack an Agora.cgi session and perform actions as a legitimate user. A number of other cross-site scripting attacks are also possible.

Exploit / POC

Agora.CGI Debug Mode Cross-Site Scripting Vulnerability

"Tamer Sahin" <[email protected]> provided the following example:

http://agorasite/store/agora.cgi?cart_id=<script>alert(document
.cookie)</script>&xm=on&product=HTML

Solution / Fix

Agora.CGI Debug Mode Cross-Site Scripting Vulnerability

Solution:
This issue has been addressed in versions 4.0e and later. Affected users are advised to upgrade.

This vulnerability is ONLY present when debug mode is enabled. Debug mode is not enabled by default. Administrators must manually enable it through the configuration interface. Disabling debug mode will completely eliminate this vulnerability.

Web users can disable the execution of JavaScript using the security features of their browser.


Agora.cgi Agora.cgi 3.2 a

Agora.cgi Agora.cgi 3.2 e

Agora.cgi Agora.cgi 3.2 d

Agora.cgi Agora.cgi 3.2 h

Agora.cgi Agora.cgi 3.2 i

Agora.cgi Agora.cgi 3.2 n

Agora.cgi Agora.cgi 3.2 j

Agora.cgi Agora.cgi 3.2 m

Agora.cgi Agora.cgi 3.2 k

Agora.cgi Agora.cgi 3.2 q

Agora.cgi Agora.cgi 3.2 l

Agora.cgi Agora.cgi 3.2

Agora.cgi Agora.cgi 3.2 ja

Agora.cgi Agora.cgi 3.2 f

Agora.cgi Agora.cgi 3.2 r

Agora.cgi Agora.cgi 3.2 c

Agora.cgi Agora.cgi 3.2 g

Agora.cgi Agora.cgi 3.2 b

Agora.cgi Agora.cgi 3.2 p

Agora.cgi Agora.cgi 3.3 f

Agora.cgi Agora.cgi 3.3 e

Agora.cgi Agora.cgi 3.3 b

Agora.cgi Agora.cgi 3.3 i

Agora.cgi Agora.cgi 3.3 d

Agora.cgi Agora.cgi 3.3 a

Agora.cgi Agora.cgi 3.3 j

Agora.cgi Agora.cgi 3.3 c

Agora.cgi Agora.cgi 4.0 c

Agora.cgi Agora.cgi 4.0 a

Agora.cgi Agora.cgi 4.0 b

Agora.cgi Agora.cgi 4.0 d

Agora.cgi Agora.cgi 4.0

References

Agora.CGI Debug Mode Cross-Site Scripting Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report