Vulnerabilities > Phpoutsourcing > Zorum > 3.1

DATE CVE VULNERABILITY TITLE RISK
2006-06-30 CVE-2006-3332 SQL Injection vulnerability in Zorum
SQL injection vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to execute arbitrary SQL commands via the (1) offset, (2) tid, (3) fromid, (4) sortby, (5) fromfrommethod, and (6) fromfromlist parameters.
network
low complexity
phpoutsourcing
7.5
2005-12-31 CVE-2005-4619 SQL Injection vulnerability in PHPOutsourcing Zorum RollID
SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the rollid parameter in the showhtmllist method.
network
low complexity
phpoutsourcing
7.5
2003-08-11 CVE-2003-1088 Cross-Site Scripting vulnerability in PHPOutSourcing Zorum
Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML via the method parameter.
network
phpoutsourcing
4.3