Vulnerabilities > Zoneo Soft

DATE CVE VULNERABILITY TITLE RISK
2006-03-02 CVE-2006-0957 Remote PHP Script Code Injection vulnerability in freeForum
Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php.
network
low complexity
zoneo-soft
7.5
2005-11-26 CVE-2005-3816 SQL Injection vulnerability in FreeForum
Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or (2) thread parameter in thread mode.
network
low complexity
zoneo-soft
7.5