Vulnerabilities > W Agora > Medium

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-1563 Remote Input Validation vulnerability in W-Agora 4.1.6A
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php.
network
w-agora
4.3
2002-12-31 CVE-2002-2129 Cross-Site Scripting vulnerability in W-Agora 4.1.5
Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary form field name containing the script, which is echoed back to the user when displaying the form.
network
w-agora
4.3
2002-12-31 CVE-2002-2128 Unspecified vulnerability in W-Agora 4.1.5
editform.php in w-Agora 4.1.5 allows local users to execute arbitrary PHP code via ..
local
low complexity
w-agora
4.6
2002-12-31 CVE-2002-1878 Remote File Include vulnerability in W-Agora 4.1.1/4.1.2/4.1.3
PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter.
network
low complexity
w-agora
5.0