Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses : XSS >> w-Agora Multiple Input Validation Vulnerabilities


Vulnerability Assessment Details

w-Agora Multiple Input Validation Vulnerabilities

Vulnerability Assessment Summary
Checks for vulnerabilities in w-Agora

Detailed Explanation for this Vulnerability Assessment

The remote host is running w-agora, a web-based forum management software
written in PHP.

There are multiple input validation flaws in the remote version of this
software :

- There is an SQL injection vulnerability in the file 'redir_url.php' which
may permit a possible hacker to execute arbitrary SQL statements in the remote
database


- There is a cross site scripting issue which may permit a possible hacker to
steal the cookies of the legitimate users of the remote site by sending them
a specially malformed link


- There is an HTTP response splitting vulnerability which may also permit
a possible hacker to perform cross-site scripting attacks against the remote host.

Solution : Upgrade to the newest version of this software
Network Security Threat Level: High

Networks Security ID: 11283

Vulnerability Assessment Copyright: This script is Copyright (C) 2004-2007 Tenable Network Security

Cables, Connectors


Apple Mac Powerbook Duo 230 Vintage Laptop picture

Apple Mac Powerbook Duo 230 Vintage Laptop

$60.00



Vintage Apple Macintosh SE Case - Empty Shell - Housing retro project picture

Vintage Apple Macintosh SE Case - Empty Shell - Housing retro project

$60.00



Vintage Apple Macintosh II 2 M5000 Computer no power very nice w drives card picture

Vintage Apple Macintosh II 2 M5000 Computer no power very nice w drives card

$350.00



Vintage Apple Macintosh Powerbook 190 Series M3047 Laptop Parts/Repair picture

Vintage Apple Macintosh Powerbook 190 Series M3047 Laptop Parts/Repair

$69.00



VINTAGE REFURBISHED MACINTOSH SE WITH BLUESCSI RECAPPED POWER SUPPLY picture

VINTAGE REFURBISHED MACINTOSH SE WITH BLUESCSI RECAPPED POWER SUPPLY

$300.00



Apple Mac IIsi computer Very Good condition  Vintage picture

Apple Mac IIsi computer Very Good condition Vintage

$100.00



VINTAGE APPLE MACINTOSH PLUS 1MB M0001A + Power Cord : POWERS ON -- UNTESTED picture

VINTAGE APPLE MACINTOSH PLUS 1MB M0001A + Power Cord : POWERS ON -- UNTESTED

$199.99



Apple Studio Display Monitor M2454 15

Apple Studio Display Monitor M2454 15" vintage Mac LCD

$80.00



Vintage Apple Power Macintosh PC Computer M3979 7600/132 picture

Vintage Apple Power Macintosh PC Computer M3979 7600/132

$249.50



Vintage Apple Macintosh Quadra Computer Incomplete READ picture

Vintage Apple Macintosh Quadra Computer Incomplete READ

$299.00



Discussions

No Discussions have been posted on this vulnerability.