exploit-db-mirror/exploits/php/webapps/22109.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

9 lines
No EOL
667 B
Text

source: http://www.securityfocus.com/bid/6464/info
W-Agora is a freely available, open source PHP forum software package. It is available for Unix and Linux systems.
A problem with W-Agora may make cross-site scripting attacks possible.
It has been reported that W-Agora has a vulnerability in the handling of script code. It is possible to format a malicious link containing arbitrary script code or HTML that when clicked on would execute in the security context of the vulnerable site. This would result in a browser security violation, and could lead to the theft of authentication cookies of administrators.
<URL:/editform.php?site=agora&blah=">Bug!>