CVE-2007-5231
Zomplog - Improper Input Validation
Title source: ruleDescription
Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2007-5230.
Exploits (1)
Scores
EPSS
0.0433
EPSS Percentile
88.9%
Details
CWE
CWE-20
Status
published
Products (4)
zomplog/zomplog
3.7
zomplog/zomplog
3.7.6
zomplog/zomplog
3.8
zomplog/zomplog
3.8.1
Published
Oct 05, 2007
Tracked Since
Feb 18, 2026