Zomplog 3.8.2 and previous versions allows remote malicious users to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
zomp zomplog |