PT-2004-2470 · W Agora · W-Agora

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-1562

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions w-Agora version 4.1.6a
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the key parameter in the redir url.php file.
Recommendations For w-Agora version 4.1.6a, consider restricting access to the redir url.php file until a patch is available, and avoid using the key parameter in this file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1562

Affected Products

W-Agora