CVE-2008-2349
zomplog < 3.8.2 - Unauthenticated Admin Account Creation via install/newuser.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2349. PoCs published by ArxWolf.
AI-analyzed exploit summary This exploit leverages an insecure installation script in Zomplog 3.8.2, where the 'install/newuser.php' file is not removed after setup, allowing unauthenticated users to create an admin account via a crafted POST request.
Description
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.
Exploits (1)
This exploit leverages an insecure installation script in Zomplog 3.8.2, where the 'install/newuser.php' file is not removed after setup, allowing unauthenticated users to create an admin account via a crafted POST request.