Total vulnerabilities in the database
Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php.
Software | From | Fixed in |
---|---|---|
zoneo-soft / freeforum | 1.1 | 1.1.x |
zoneo-soft / freeforum | 1.1.2 | 1.1.2.x |
zoneo-soft / freeforum | 1.2 | 1.2.x |
zoneo-soft / freeforum | 1.0.1 | 1.0.1.x |
zoneo-soft / freeforum | 1.1.1 | 1.1.1.x |
zoneo-soft / freeforum | 1.0 | 1.0.x |