漏洞信息详情
W-Agora多个远程输入验证漏洞
漏洞简介
w-Agora 4.1.6a版本中的redir_url.php存在SQL注入漏洞。远程攻击者可以借助key参数执行任意SQL命令。
漏洞公告
It is reported that CVS patches are available to address these issues. Please contact the vendor for more information. A link to the W-Agora CVS repository is available in Web references.
参考网址
来源: XF 名称: wagora-redirurl-sql-injection(17557) 链接:http://xforce.iss.net/xforce/xfdb/17557 来源: SECUNIA 名称: 12695 链接:http://secunia.com/advisories/12695 来源: BID 名称: 11283 链接:http://www.securityfocus.com/bid/11283 来源: BUGTRAQ 名称: 20040930 Multiple vulnerabilities in w-agora forum 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=109655691512298&w=2 来源: FULLDISC 名称: 20040930 Multiple vulnerabilities in w-agora forum 链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html 来源: SECTRACK 名称: 1011463 链接:http://securitytracker.com/id?1011463
受影响实体
- W-Agora W-Agora:4.1.6a<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...