Zoneo Soft's vulnerability footprint centers on a small set of web-application products including PHP Traffic and Free Forum, which occupy a niche segment of the broader application landscape. The vendor's disclosures reflect the characteristic input-handling and access-control concerns found in self-hosted web applications, and live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zoneo Soft over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3427HIGH SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a stats action. | Jun 27, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-3816HIGH Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or ( | Nov 26, 2005 | 7.5 | 28 | NO | YES |
CVE-2007-3647HIGH The isloggedin function in Php/login.inc.php in phpTrafficA 1.4.3 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the usern | Jul 10, 2007 | 10.0 | 25 | NO | NO |
CVE-2008-3566MEDIUM Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter to (1) the default UR | Aug 10, 2008 | 4.3 | 23 | NO | YES |
CVE-2007-3425MEDIUM Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbitrary local files via the lang parameter, a different vector | Jun 27, 2007 | 5.0 | 23 | NO | YES |
CVE-2007-3426MEDIUM Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | Jun 27, 2007 | 4.3 | 21 | NO | YES |
CVE-2014-8340HIGH SQL injection vulnerability in Php/Functions/log_function.php in phpTrafficA 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via a User-Agent HTTP header. | Dec 16, 2014 | 7.5 | 20 | NO | NO |
CVE-2007-3428HIGH Multiple unspecified vulnerabilities in phpTrafficA before 1.4.2 allow remote attackers to have an unknown impact via the file parameter to (1) plotStatBar.php or (2) plotStatPie.p | Jun 27, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-0487HIGH PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue has | Jan 25, 2007 | 7.5 | 19 | NO | NO |
CVE-2006-0957HIGH Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For an | Mar 2, 2006 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zoneo Soft.
Media articles that mention a CVE ID that affects a product developed by Zoneo Soft — matched by CVE ID, not by vendor name.