BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
w-agora [multiples file upload,xss,full path disclosure,error sql] Mar 20 2007 04:07PM
none none com
vendor website: http://www.w-agora.com/
bug: multiples file upload,xss,full path disclosure,error sql
global risk: critical

file upload :
there's actually 2 ways to upload a file on w-agora :

1)on the forum you can post some attached file with your message and you can upload any kind of file
the...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus