admin/cron.php in eSyndicat Directory 1.2, when registerglobals is enabled and magicquotesgpc is disabled, allows remote attackers to include arbitrary files and possibly execute arbitrary PHP code via a null-terminated value in the pathtoconfig parameter.
Multiple SQL injection vulnerabilities in eSyndiCat allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php or (2) the name parameter to page.php.