Vulnerabilities > W Agora > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2004-12-31 | CVE-2004-1563 | Remote Input Validation vulnerability in W-Agora 4.1.6A Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php. network w-agora | 4.3 |
2002-12-31 | CVE-2002-2129 | Cross-Site Scripting vulnerability in W-Agora 4.1.5 Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary form field name containing the script, which is echoed back to the user when displaying the form. network w-agora | 4.3 |
2002-12-31 | CVE-2002-2128 | Unspecified vulnerability in W-Agora 4.1.5 editform.php in w-Agora 4.1.5 allows local users to execute arbitrary PHP code via .. | 4.6 |
2002-12-31 | CVE-2002-1878 | Remote File Include vulnerability in W-Agora 4.1.1/4.1.2/4.1.3 PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter. | 5.0 |