PT-2007-2065 · W Agora · W-Agora

Jesper Jurcenoks

+1

·

Published

2007-03-20

·

Updated

2018-10-16

·

CVE-2007-0607

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions W-Agora (Web-Agora) version 4.2.1
Description The issue allows remote attackers to obtain application path information via a direct request to the globals.inc file, which is stored under the web document root with insufficient access control when register globals is enabled.
Recommendations For W-Agora (Web-Agora) version 4.2.1, consider disabling the register globals setting to prevent remote attackers from accessing sensitive information. Additionally, restrict access to the globals.inc file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0607

Affected Products

W-Agora