CVE-2008-2349

Zomplog < 3.8.2 - Access Control

Title source: rule

Description

Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ArxWolf · htmlwebappsphp
https://www.exploit-db.com/exploits/5634

Scores

EPSS 0.0565
EPSS Percentile 90.4%

Details

CWE
CWE-264
Status published
Products (1)
zomp/zomplog < 3.8.2
Published May 20, 2008
Tracked Since Feb 18, 2026