W-Agora EditForm.PHP Cross-Site Scripting Vulnerability
BID:6464
Info
W-Agora EditForm.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 6464 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2002 12:00AM |
| Updated: | Dec 22 2002 12:00AM |
| Credit: | Vulnerability discovery credited to "xatr0z" <[email protected]>. |
| Vulnerable: |
W-Agora W-Agora 4.1.6 |
| Not Vulnerable: | |
Discussion
W-Agora EditForm.PHP Cross-Site Scripting Vulnerability
W-Agora is a freely available, open source PHP forum software package. It is available for Unix and Linux systems.
A problem with W-Agora may make cross-site scripting attacks possible.
It has been reported that W-Agora has a vulnerability in the handling of script code. It is possible to format a malicious link containing arbitrary script code or HTML that when clicked on would execute in the security context of the vulnerable site. This would result in a browser security violation, and could lead to the theft of authentication cookies of administrators.
W-Agora is a freely available, open source PHP forum software package. It is available for Unix and Linux systems.
A problem with W-Agora may make cross-site scripting attacks possible.
It has been reported that W-Agora has a vulnerability in the handling of script code. It is possible to format a malicious link containing arbitrary script code or HTML that when clicked on would execute in the security context of the vulnerable site. This would result in a browser security violation, and could lead to the theft of authentication cookies of administrators.
Exploit / POC
W-Agora EditForm.PHP Cross-Site Scripting Vulnerability
<URL:/editform.php?site=agora&blah=">Bug!>
<URL:/editform.php?site=agora&blah=">Bug!>
Solution / Fix
W-Agora EditForm.PHP Cross-Site Scripting Vulnerability
Solution:
The vendor has stated that fixes will be available soon.
Solution:
The vendor has stated that fixes will be available soon.
References
W-Agora EditForm.PHP Cross-Site Scripting Vulnerability
References:
References:
- W-Agora Homepage (W-Agora)
- Re: XSS and PHP include bug in W-Agora (Marc Druilhe
) - XSS and PHP include bug in W-Agora ("xatr0z"
)