file upload :
there's actually 2 ways to upload a file on w-agora :
1)on the forum you can post some attached file with your message and you
can upload any kind of file
then your file will be located here :
site.com/w-agora/forums/hello/hello/notes/ ( hello = name of the forum )
then you can just browse :site.com/w-agora/forums/
to find out where is your file.
2) http://site.com/w-agora/browse_avatar.php?site=hello ( replace hello ,
by your forum name. )
with this script you can upload any file with a double extension like :
file.php.jpg
the file will be located here :
http://site.com/w-agora/images/avatars/file.php.jpg
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Maksymilian Arciemowicz discovered a Integer Overflow
vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.