Vulnerabilities > CVE-2006-0957 - Remote PHP Script Code Injection vulnerability in freeForum
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Packetstorm
data source | https://packetstormsecurity.com/files/download/44571/EV0089.txt |
id | PACKETSTORM:44571 |
last seen | 2016-12-05 |
published | 2006-03-11 |
reporter | Aliaksandr Hartsuyeu |
source | https://packetstormsecurity.com/files/44571/EV0089.txt.html |
title | EV0089.txt |