← Vulnerability feed

Vulnerability record · CVE-2008-1466 · published 24 March 2008

CVE-2008-1466: W-agora code injection vulnerability

W Agora · W Agora

Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default parameter to (1) add_user.php, (2) create_forum.php, (3) create_user.php, (4) delete_notes.php, (5) delete_user.php, (6) edit_forum.php, (7) mail_users.php, (8) moderate_notes.php, and (9) reorder_forums.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

7.5 CVSS 2.0 High EPSS 2.2% · top 18.0% CWE-94 · Code injection
7.5CVSS 2.0 base score
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default parameter to (1) add_user.php, (2) create_forum.php, (3) create_user.php, (4) delete_notes.php, (5) delete_user.php, (6) edit_forum.php, (7) mail_users.php, (8) moderate_notes.php, and (9) reorder_forums.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1466 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2010-4867W-agora path traversal vulnerabilityDirectory traversal vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to include and execute arbitra…EPSS 2.4%7.5CVE-2007-6647W-agora sql injection vulnerabilitySQL injection vulnerability in index.php in w-Agora 4.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.EPSS 1.0%7.5CVE-2007-1604W-agora vulnerabilityMultiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a fo…EPSS 3.0%7.5CVE-2004-1562W-agora vulnerabilitySQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter.EPSS 1.4%5.0CVE-2007-1605W-agora vulnerabilityw-Agora (Web-Agora) allows remote attackers to obtain sensitive information via a request to rss.php with an invalid (1) site or (2) bn parameter, (3…EPSS 1.7%5.0CVE-2007-1607W-agora vulnerabilitysearch.php in w-Agora (Web-Agora) allows remote attackers to obtain potentially sensitive information via a ' (quote) value followed by certain SQL s…EPSS 2.3%5.0CVE-2007-0606W-agora vulnerabilityw-agora 4.2.1 allows remote attackers to obtain sensitive information by via the (1) bn[] array parameter to index.php, which expects a string, and (…EPSS 1.6%5.0CVE-2005-2648W-agora vulnerabilityDirectory traversal vulnerability in index.php in W-Agora 4.2.0 and earlier allows remote attackers to read arbitrary files via the site parameter.EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2008-1466), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.