PT-2002-2848 · W Agora · W-Agora
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2128
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
w-Agora version 4.1.5
Description:
The issue allows local users to execute arbitrary PHP code. This is achieved by utilizing .. (dot dot) sequences in the
file parameter of the editform.php script.Recommendations:
For w-Agora version 4.1.5, consider restricting access to the editform.php script to prevent exploitation until a patch is available. As a temporary workaround, avoid using the
file parameter in the editform.php script until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
W-Agora