SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the rollid parameter in the showhtmllist method.
| Software | From | Fixed in |
|---|---|---|
| phpoutsourcing / zorum | 3.3 | 3.3.x |
| phpoutsourcing / zorum | 3.5 | 3.5.x |
| phpoutsourcing / zorum | 3.4 | 3.4.x |
| phpoutsourcing / zorum | 3.2 | 3.2.x |
| phpoutsourcing / zorum | 3.0 | 3.0.x |
| phpoutsourcing / zorum | 3.1 | 3.1.x |