7.5
CVSSv2

CVE-2007-1604

Published: 22/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote malicious users to upload and execute arbitrary PHP code (1) via a forum message with an attached file, which is stored under forums/hello/hello/notes/ or (2) by using browse_avatar.php to upload a file with a double extension, as demonstrated by .php.jpg.

Vulnerable Product Search on Vulmon Subscribe to Product

w-agora w-agora 4.2.1

Exploits

source: wwwsecurityfocuscom/bid/23055/info w-Agora is prone to multiple arbitrary file-upload vulnerabilities An attacker can exploit these vulnerabilities to upload PHP script code and execute it in the context of the webserver process w-Agora 421 is vulnerable <?php /* Title : w-Agora Forum 421 Remot ...