Skip to content
Noroxi

Zomplog records

8 published records for vendor zomplog.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    8 records
    • CVE-2007-2157
      32Monitor

      Directory traversal vulnerability in upload/force_download.php in Zomplog 3.8 allows remote attackers to read arbitrary files via a ..

      HighCVSS 7.8Proof of conceptEPSS 4%

      zomplog · zomplogApr 19, 2007

    • CVE-2007-5230
      31Monitor

      admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform

      HighCVSS 7.5Proof of conceptEPSS 5%

      zomplog · zomplogOct 5, 2007

    • CVE-2007-2773
      31Monitor

      SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and earlier allows remote attackers to execute arbitrary S

      HighCVSS 7.5Proof of conceptEPSS 2%

      zomplog · zomplogMay 21, 2007

    • CVE-2005-3309
      30Monitor

      Multiple SQL injection vulnerabilities in Zomplog 3.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in d

      HighCVSS 7.5No exploitEPSS 1%

      zomplog · zomplogOct 25, 2005

    • CVE-2007-1524
      21Monitor

      Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files v

      MediumCVSS 5.0Proof of conceptEPSS 3%

      zomplog · zomplogMar 20, 2007

    • CVE-2007-5231
      19Monitor

      Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to

      MediumCVSS 4.6Proof of conceptEPSS 2%

      zomplog · zomplogOct 5, 2007

    • CVE-2005-3308
      18Monitor

      Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1)

      MediumCVSS 4.3Proof of conceptEPSS 2%

      zomplog · zomplogOct 25, 2005

    • CVE-2007-5278
      18Monitor

      Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote

      MediumCVSS 4.3Proof of conceptEPSS 2%

      zomplog · zomplogOct 8, 2007