BugTraq
Back to list
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
w-agora [multiples file upload,xss,full path disclosure,error sql]
Mar 20 2007 04:07PM
none none com
vendor website: http://www.w-agora.com/
bug: multiples file upload,xss,full path disclosure,error sql
global risk: critical
file upload :
there's actually 2 ways to upload a file on w-agora :
1)on the forum you can post some attached file with your message and you can upload any kind of file
the...
[ more ]
Privacy Statement
Copyright 2010, SecurityFocus
bug: multiples file upload,xss,full path disclosure,error sql
global risk: critical
file upload :
there's actually 2 ways to upload a file on w-agora :
1)on the forum you can post some attached file with your message and you can upload any kind of file
the...
[ more ]