Vulnerabilities
Vulnerable Software
Zomplog:  >> Zomplog  >> 3.7.6  Security Vulnerabilities
admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administrative actions via a direct request. NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231.
CVSS Score
7.5
EPSS Score
0.052
Published
2007-10-05
Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2007-5230.
CVSS Score
4.6
EPSS Score
0.025
Published
2007-10-05
Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then be included via themes/default/.
CVSS Score
5.0
EPSS Score
0.038
Published
2007-03-20


Contact Us

Shodan ® - All rights reserved