PT-2002-2848 · W Agora · W-Agora

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-2128

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: w-Agora version 4.1.5
Description: The issue allows local users to execute arbitrary PHP code. This is achieved by utilizing .. (dot dot) sequences in the file parameter of the editform.php script.
Recommendations: For w-Agora version 4.1.5, consider restricting access to the editform.php script to prevent exploitation until a patch is available. As a temporary workaround, avoid using the file parameter in the editform.php script until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-2128

Affected Products

W-Agora