Vulnerability Details CVE-2010-4867
Directory traversal vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bn parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.038
EPSS Ranking 87.5%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2010-4867
-
cpe:2.3:a:w-agora:w-agora:*
-
cpe:2.3:a:w-agora:w-agora:4.0.0
-
cpe:2.3:a:w-agora:w-agora:4.0.1
-
cpe:2.3:a:w-agora:w-agora:4.0.2
-
cpe:2.3:a:w-agora:w-agora:4.0.2a
-
cpe:2.3:a:w-agora:w-agora:4.0.3
-
cpe:2.3:a:w-agora:w-agora:4.1.0
-
cpe:2.3:a:w-agora:w-agora:4.1.1
-
cpe:2.3:a:w-agora:w-agora:4.1.2
-
cpe:2.3:a:w-agora:w-agora:4.1.3
-
cpe:2.3:a:w-agora:w-agora:4.1.4
-
cpe:2.3:a:w-agora:w-agora:4.1.5
-
cpe:2.3:a:w-agora:w-agora:4.1.6
-
cpe:2.3:a:w-agora:w-agora:4.1.6a
-
cpe:2.3:a:w-agora:w-agora:4.1.7
-
cpe:2.3:a:w-agora:w-agora:4.2.0