Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

W-Agora EditForm.PHP Cross-Site Scripting Vulnerability

W-Agora is a freely available, open source PHP forum software package. It is available for Unix and Linux systems.

A problem with W-Agora may make cross-site scripting attacks possible.

It has been reported that W-Agora has a vulnerability in the handling of script code. It is possible to format a malicious link containing arbitrary script code or HTML that when clicked on would execute in the security context of the vulnerable site. This would result in a browser security violation, and could lead to the theft of authentication cookies of administrators.







 

Privacy Statement
Copyright 2009, SecurityFocus