Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

W Agora HIGH 7.5
CVE-2010-4867

Directory traversal vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to include and execute arbitra…

Fix: after 4.2.1
Fix from $1,950 2011-10-05
W Agora HIGH 7.5
CVE-2008-1466

Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_defaul…

No fix yet
Fix from $1,950 2008-03-24
W Agora HIGH 7.5
CVE-2007-6647

SQL injection vulnerability in index.php in w-Agora 4.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.

Fix: after 4.2.1
Fix from $1,950 2008-01-04
W Agora HIGH 7.5
CVE-2007-1604

Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a fo…

No fix yet
Fix from $1,950 2007-03-22
W Agora MEDIUM 5.0
CVE-2007-1605

w-Agora (Web-Agora) allows remote attackers to obtain sensitive information via a request to rss.php with an invalid (1) site or (2) bn parameter, (3…

No fix yet
Fix from $1,600 2007-03-22
W Agora MEDIUM 5.0
CVE-2007-1607

search.php in w-Agora (Web-Agora) allows remote attackers to obtain potentially sensitive information via a ' (quote) value followed by certain SQL s…

No fix yet
Fix from $1,600 2007-03-22
W Agora MEDIUM 5.0
CVE-2007-0606

w-agora 4.2.1 allows remote attackers to obtain sensitive information by via the (1) bn[] array parameter to index.php, which expects a string, and (…

No fix yet
Fix from $1,600 2007-03-21
W Agora MEDIUM 5.0
CVE-2005-2648

Directory traversal vulnerability in index.php in W-Agora 4.2.0 and earlier allows remote attackers to read arbitrary files via the site parameter.

No fix yet
Fix from $1,600 2005-08-23
W Agora HIGH 7.5
CVE-2004-1562

SQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter.

Patch available
Fix from $1,950 2004-12-31
W Agora MEDIUM 5.0
CVE-2004-1564EPSS 6%

CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify e…

Patch available
Fix from $1,600 2004-12-31
W Agora MEDIUM 5.0
CVE-2004-1565

list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.

Patch available
Fix from $1,600 2004-12-31
W Agora MEDIUM 5.0
CVE-2002-1878

PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter.

Patch available
Fix from $1,600 2002-12-31