Skip to main content

Vendor archive

zoneo-soft CVEs

Beta · best-effort

13 CVEs tagged to vendor zoneo-soft1 Critical, 6 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2015-2926

Published Apr 14, 2015

Cross-site scripting (XSS) vulnerability in Php/stats/statsRecent.inc.php in phpTrafficA 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8340

Published Dec 16, 2014

SQL injection vulnerability in Php/Functions/log_function.php in phpTrafficA 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via a User-Agent HTTP header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3566

Published Aug 10, 2008

Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter to (1) the default U…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3647

Published Jul 10, 2007

The isloggedin function in Php/login.inc.php in phpTrafficA 1.4.3 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the user…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-7209

Published Jun 27, 2007

Multiple cross-site scripting (XSS) vulnerabilities in phpTrafficA before 1.2beta2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3425

Published Jun 27, 2007

Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbitrary local files via the lang parameter, a different vector…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3426

Published Jun 27, 2007

Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3427

Published Jun 27, 2007

SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a stats action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3428

Published Jun 27, 2007

Multiple unspecified vulnerabilities in phpTrafficA before 1.4.2 allow remote attackers to have an unknown impact via the file parameter to (1) plotStatBar.php or (2) plotStatPie.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0487

Published Jan 25, 2007

PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue ha…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0957

Published Mar 2, 2006

Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0958

Published Mar 2, 2006

Cross-site scripting (XSS) vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3816

Published Nov 26, 2005

Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1