CVE-2004-1563

Properties

Published:
30.12.2004
Updated:
20.10.2005
Patch available:
Severity:
Low
  • CVSS vector:
    (AV:R/AC:L/Au:NR/C:N/I:C/A:N/B:N) Approximated
    Product:
    W-Agora: W-Agora

    Vulnerability description

    Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php.

    References:

    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109655691512298&w=2
    FULLDISC: http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html
    BID: http://www.securityfocus.com/bid/11283
    SECUNIA: http://secunia.com/advisories/12695
    XF: http://xforce.iss.net/xforce/xfdb/17553
    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109655691512298&w=2
    SECTRACK: http://securitytracker.com/id?1011463