CVE-2007-1524

Zomplog - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then be included via themes/default/.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Bl0od3r · perlwebappsphp
https://www.exploit-db.com/exploits/3476

Scores

EPSS 0.0729
EPSS Percentile 91.7%

Details

Status published
Products (1)
zomplog/zomplog 3.7.6
Published Mar 20, 2007
Tracked Since Feb 18, 2026