W-Agora Multiple Remote Vulnerabilities
BID:9226
Info
W-Agora Multiple Remote Vulnerabilities
| Bugtraq ID: | 9226 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2003 12:00AM |
| Updated: | Dec 15 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to the vendor. |
| Vulnerable: |
W-Agora W-Agora 4.1.5 |
| Not Vulnerable: |
W-Agora W-Agora 4.1.6 |
Discussion
W-Agora Multiple Remote Vulnerabilities
It has been reported that W-Agora may be prone to multiple vulnerabilities resulting from insufficient sanitization of user-supplied input. The software is reportedly vulnerable to cross-site scripting and remote file include attacks. Successful exploitation of these issues may allow a remote attacker to steal cookie-based authentication credentials or include malicious scripts to be executed on a vulnerable system.
W-Agora version 4.1.5 has been reported to be prone to this issue, however other versions may be affected as well.
These issues are currently undergoing further analysis. This cumulative BID will be separated into individual entries when analysis is complete.
It has been reported that W-Agora may be prone to multiple vulnerabilities resulting from insufficient sanitization of user-supplied input. The software is reportedly vulnerable to cross-site scripting and remote file include attacks. Successful exploitation of these issues may allow a remote attacker to steal cookie-based authentication credentials or include malicious scripts to be executed on a vulnerable system.
W-Agora version 4.1.5 has been reported to be prone to this issue, however other versions may be affected as well.
These issues are currently undergoing further analysis. This cumulative BID will be separated into individual entries when analysis is complete.
Exploit / POC
W-Agora Multiple Remote Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
W-Agora Multiple Remote Vulnerabilities
Solution:
The vendor has released W-Agora version 4.1.6 to address these issues.
W-Agora W-Agora 4.1.5
Solution:
The vendor has released W-Agora version 4.1.6 to address these issues.
W-Agora W-Agora 4.1.5
-
W-Agora w-agora-4.1.6-php.tar.gz
http://www.w-agora.com/current/getfile.php/support_dl/543/w-agora-4.1. 6-php.tar.gz