Vulnerabilities > Zoneo Soft > High

DATE CVE VULNERABILITY TITLE RISK
2014-12-16 CVE-2014-8340 SQL Injection vulnerability in Zoneo-Soft PHPtraffica 2.2.1
SQL injection vulnerability in Php/Functions/log_function.php in phpTrafficA 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via a User-Agent HTTP header.
network
low complexity
zoneo-soft CWE-89
7.5
2007-06-27 CVE-2007-3428 Remote Security vulnerability in phpTrafficA
Multiple unspecified vulnerabilities in phpTrafficA before 1.4.2 allow remote attackers to have an unknown impact via the file parameter to (1) plotStatBar.php or (2) plotStatPie.php, different vectors than CVE-2007-1076.
network
low complexity
zoneo-soft
7.5
2007-06-27 CVE-2007-3427 SQL-Injection vulnerability in phpTrafficA
SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a stats action.
network
low complexity
zoneo-soft
7.5
2006-03-02 CVE-2006-0957 Remote PHP Script Code Injection vulnerability in freeForum
Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php.
network
low complexity
zoneo-soft
7.5
2005-11-26 CVE-2005-3816 SQL Injection vulnerability in FreeForum
Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or (2) thread parameter in thread mode.
network
low complexity
zoneo-soft
7.5