|
W-Agora Multiple Input Validation Vulnerabilities
An attacker can exploit an SQL-injection vulnerability via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim to follow a malicious URI. The following example URIs are available: http://www.example.com/w-agora/search.php?bn=hello_hello&gosearch=1&pattern=1&search_date=0&search_fields[body]=1&search_fields[ subject]=1&search_forum='[sql] http://www.example.com/w-agora/search.php?bn=hello_hello&gosearch=1&pattern=1&search_date=0&search_fields[body]=1&search_fields[ subject]=1&search_forum=hello_hello&search_mode=0&search_user='[sql] |
|
|
Privacy Statement |