4.3
CVSSv2

CVE-2002-2129

Published: 31/12/2002 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote malicious users to execute arbitrary web script via an arbitrary form field name containing the script, which is echoed back to the user when displaying the form.

Vulnerable Product Search on Vulmon Subscribe to Product

w-agora w-agora 4.1.5

Exploits

source: wwwsecurityfocuscom/bid/6464/info W-Agora is a freely available, open source PHP forum software package It is available for Unix and Linux systems A problem with W-Agora may make cross-site scripting attacks possible It has been reported that W-Agora has a vulnerability in the handling of script code It is possible to format ...