SQL injection vulnerability in kroax.php in the Kroax (thekroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the category parameter.
Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter to (1) forum.php and (2) profile.php in infusions/ranksystem/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.