Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freeforum | Zoneo-soft | 1.0 (including) | 1.0 (including) |
Freeforum | Zoneo-soft | 1.0.1 (including) | 1.0.1 (including) |
Freeforum | Zoneo-soft | 1.1 (including) | 1.1 (including) |
Freeforum | Zoneo-soft | 1.1.1 (including) | 1.1.1 (including) |
Freeforum | Zoneo-soft | 1.1.2 (including) | 1.1.2 (including) |
Freeforum | Zoneo-soft | 1.2 (including) | 1.2 (including) |