Vulnerabilities > CVE-2007-1606 - Cross-Site Scripting vulnerability in W-Agora 4.2.1

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
w-agora
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the showuser parameter to profile.php, the (2) search_forum or (3) search_user parameter to search.php, or (4) the userid parameter to change_password.php.

Vulnerable Configurations

Part Description Count
Application
W-Agora
1

Exploit-Db

  • descriptionW-Agora 4.2.1 change_password.php userid Parameter XSS. CVE-2007-1606. Webapps exploit for php platform
    idEDB-ID:29766
    last seen2016-02-03
    modified2007-03-20
    published2007-03-20
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/29766/
    titleW-Agora 4.2.1 change_password.php userid Parameter XSS
  • descriptionW-Agora 4.2.1 profile.php showuser Parameter XSS. CVE-2007-1606. Webapps exploit for php platform
    idEDB-ID:29764
    last seen2016-02-03
    modified2007-03-20
    published2007-03-20
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/29764/
    titleW-Agora 4.2.1 profile.php showuser Parameter XSS
  • descriptionW-Agora 4.2.1 search.php search_user Parameter XSS. CVE-2007-1606 . Webapps exploit for php platform
    idEDB-ID:29765
    last seen2016-02-03
    modified2007-03-20
    published2007-03-20
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/29765/
    titleW-Agora 4.2.1 - search.php search_user Parameter XSS