Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2010-4867 Directory traversal vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to include and execute arbitra… W Agora after 4.2.1 Fix from $1,9502011-10-05 HIGH 7.5 CVE-2008-1466 Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_defaul… W Agora No fix yet Fix from $1,9502008-03-24 HIGH 7.5 CVE-2007-6647 SQL injection vulnerability in index.php in w-Agora 4.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. W Agora after 4.2.1 Fix from $1,9502008-01-04 HIGH 7.5 CVE-2007-1604 Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a fo… W Agora No fix yet Fix from $1,9502007-03-22 MEDIUM 5.0 CVE-2007-1605 w-Agora (Web-Agora) allows remote attackers to obtain sensitive information via a request to rss.php with an invalid (1) site or (2) bn parameter, (3… W Agora No fix yet Fix from $1,6002007-03-22 MEDIUM 5.0 CVE-2007-1607 search.php in w-Agora (Web-Agora) allows remote attackers to obtain potentially sensitive information via a ' (quote) value followed by certain SQL s… W Agora No fix yet Fix from $1,6002007-03-22 MEDIUM 5.0 CVE-2007-0606 w-agora 4.2.1 allows remote attackers to obtain sensitive information by via the (1) bn[] array parameter to index.php, which expects a string, and (… W Agora No fix yet Fix from $1,6002007-03-21 MEDIUM 5.0 CVE-2005-2648 Directory traversal vulnerability in index.php in W-Agora 4.2.0 and earlier allows remote attackers to read arbitrary files via the site parameter. W Agora No fix yet Fix from $1,6002005-08-23 HIGH 7.5 CVE-2004-1562 SQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter. W Agora Patch available Fix from $1,9502004-12-31 MEDIUM 5.0 CVE-2004-1564EPSS 6% CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify e… W Agora Patch available Fix from $1,6002004-12-31 MEDIUM 5.0 CVE-2004-1565 list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter. W Agora Patch available Fix from $1,6002004-12-31 MEDIUM 5.0 CVE-2002-1878 PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter. W Agora Patch available Fix from $1,6002002-12-31