Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zomplog zomplog vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-5231
Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and previous versions allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. NOTE: this can be exploited by unauthenticated attackers ...
Zomplog Zomplog 3.8
Zomplog Zomplog 3.8.1
Zomplog Zomplog 3.7
Zomplog Zomplog 3.7.6
1 EDB exploit
NA
CVE-2007-5230
admin/upload_files.php in Zomplog 3.8.1 and previous versions does not check for administrative credentials, which allows remote malicious users to perform administrative actions via a direct request. NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231.
Zomplog Zomplog 3.7.6
Zomplog Zomplog 3.8
Zomplog Zomplog 3.8.1
Zomplog Zomplog 3.7
1 EDB exploit
NA
CVE-2005-3308
Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote malicious users to inject arbitrary web script or HTML via the (1) name or (2) comment parameter in detail.php, (3) the username parameter in get.php, and (4) the search parameter in index.php.
Zomplog Zomplog 3.3
Zomplog Zomplog 3.4
1 EDB exploit
NA
CVE-2007-2773
SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and previous versions allows remote malicious users to execute arbitrary SQL commands via the speler parameter.
Zomplog Zomplog
1 EDB exploit
NA
CVE-2007-5278
Zomplog 3.8.1 and previous versions stores potentially sensitive information under the web root with insufficient access control, which allows remote malicious users to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct reque...
Zomplog Zomplog 3.8.1
1 EDB exploit
NA
CVE-2007-2157
Directory traversal vulnerability in upload/force_download.php in Zomplog 3.8 allows remote malicious users to read arbitrary files via a .. (dot dot) in the file parameter.
Zomplog Zomplog 3.8
1 EDB exploit
NA
CVE-2007-1524
Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and previous versions allows remote malicious users to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file...
Zomplog Zomplog 3.7.6
1 EDB exploit
NA
CVE-2005-3309
Multiple SQL injection vulnerabilities in Zomplog 3.4 allow remote malicious users to execute arbitrary SQL commands via (1) the id parameter in detail.php and the catid parameter in (2) get.php and (3) index.php.
Zomplog Zomplog 3.4
NA
CVE-2008-2349
Zomplog 3.8.2 and previous versions allows remote malicious users to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.
Zomp Zomplog
1 EDB exploit
NA
CVE-2008-2176
Cross-site scripting (XSS) vulnerability in admin/category.php in Zomplog 3.8.2 allows remote malicious users to inject arbitrary web script or HTML via the catname parameter.
Zomp Zomplog 3.8.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started