Molteplici cross-site scripting (XSS) vulnerabilità nel w-Agora 4.1.6a consentire ad aggressori remoti di eseguire lo script Web arbitrario o HTML tramite il parametro filo (1) a download_thread.php, (2) il parametro LoginUser a login.php, o ( 3) userid parametro forgot_password.php. |
http://www.securityfocus.com/bid/11283 http://marc.info/?l=bugtraq&m=109655691512298&w=2 http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html http://securitytracker.com/id?1011463 http://secunia.com/advisories/12695 https://exchange.xforce.ibmcloud.com/vulnerabilities/17553 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1563 |
Vulnerabilità: CVE-2004-1563
