CVE-2007-0607

W-Agora (Web-Agora) 4.2.1, when register_globals is enabled, stores globals.inc under the web document root with insufficient access control, which allows remote attackers to obtain application path information via a direct request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:w-agora:w-agora:4.2.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-03-20 20:19

Updated : 2024-02-04 17:13


NVD link : CVE-2007-0607

Mitre link : CVE-2007-0607

CVE.ORG link : CVE-2007-0607


JSON object : View

Products Affected

w-agora

  • w-agora