CVE-2004-1565

Properties

Published:
30.12.2004
Updated:
20.10.2005
Patch available:
Severity:
Low
  • CVSS vector:
    (AV:R/AC:L/Au:NR/C:C/I:N/A:N/B:N) Approximated
    Product:
    W-Agora: W-Agora

    Vulnerability description

    list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.

    References:

    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109655691512298&w=2
    FULLDISC: http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html
    BID: http://www.securityfocus.com/bid/11283
    SECUNIA: http://secunia.com/advisories/12695
    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109655691512298&w=2
    SECTRACK: http://securitytracker.com/id?1011463