Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

W-Agora Multiple Input Validation Vulnerabilities

An attacker can exploit an SQL-injection vulnerability via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim to follow a malicious URI.

The following example URIs are available:

http://www.example.com/w-agora/search.php?bn=hello_hello&gosearch=1&pattern=1&search_date=0&search_fields[body]=1&search_fields[
subject]=1&search_forum='[sql]
http://www.example.com/w-agora/search.php?bn=hello_hello&gosearch=1&pattern=1&search_date=0&search_fields[body]=1&search_fields[
subject]=1&search_forum=hello_hello&search_mode=0&search_user='[sql]







 

Privacy Statement
Copyright 2009, SecurityFocus