CVE-2004-1563
w-agora 4.1.6a - Cross-Site Scripting via Thread, Loginuser, or Userid Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2004-1563. PoCs published by Alexander Antipov.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in W-Agora 4.1.6a, including SQL injection, XSS, and HTTP response splitting due to insufficient input sanitization. It includes a sample HTTP POST request demonstrating an XSS attack vector.
Description
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php.
Exploits (3)
The provided text describes multiple vulnerabilities in W-Agora 4.1.6a, including SQL injection, XSS, and HTTP response splitting due to insufficient input sanitization. It includes a sample HTTP POST request demonstrating an XSS attack vector.
The provided text describes multiple vulnerabilities in W-Agora 4.1.6a, including SQL injection, XSS, and HTTP response splitting, with an example HTTP POST request demonstrating XSS via the 'userid' parameter. No actual exploit code is present, only a description and a template for exploitation.
The provided text describes multiple vulnerabilities in W-Agora 4.1.6a, including SQL injection, XSS, and HTTP response splitting due to insufficient input sanitization. It includes an example URL for XSS exploitation but lacks actual exploit code.