7.5

CVE-2007-5230

admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administrative actions via a direct request.  NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZomplogZomplog Version3.7
ZomplogZomplog Version3.7.6
ZomplogZomplog Version3.8
ZomplogZomplog Version3.8.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.66% 0.906
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/27028
Vendor Advisory
http://www.securityfocus.com/bid/25861
Patch
https://www.exploit-db.com/exploits/4466