Перейти к содержимому
Noroxi

Записи Zomplog

8 опубликованных записей вендора zomplog.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

    Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

    CWE

    Все записи

    8 записей
    • CVE-2007-2157
      32Наблюдать

      Directory traversal vulnerability in upload/force_download.php in Zomplog 3.8 allows remote attackers to read arbitrary files via a ..

      ВысокаяCVSS 7,8Proof of conceptEPSS 4 %

      zomplog · zomplog19 апр. 2007 г.

    • CVE-2007-5230
      31Наблюдать

      admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform

      ВысокаяCVSS 7,5Proof of conceptEPSS 5 %

      zomplog · zomplog5 окт. 2007 г.

    • CVE-2007-2773
      31Наблюдать

      SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and earlier allows remote attackers to execute arbitrary S

      ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

      zomplog · zomplog21 мая 2007 г.

    • CVE-2005-3309
      30Наблюдать

      Multiple SQL injection vulnerabilities in Zomplog 3.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in d

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      zomplog · zomplog25 окт. 2005 г.

    • CVE-2007-1524
      21Наблюдать

      Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files v

      СредняяCVSS 5,0Proof of conceptEPSS 3 %

      zomplog · zomplog20 мар. 2007 г.

    • CVE-2007-5231
      19Наблюдать

      Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to

      СредняяCVSS 4,6Proof of conceptEPSS 2 %

      zomplog · zomplog5 окт. 2007 г.

    • CVE-2005-3308
      18Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1)

      СредняяCVSS 4,3Proof of conceptEPSS 2 %

      zomplog · zomplog25 окт. 2005 г.

    • CVE-2007-5278
      18Наблюдать

      Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote

      СредняяCVSS 4,3Proof of conceptEPSS 2 %

      zomplog · zomplog8 окт. 2007 г.