RSS   Vulnerabilities for 'Zomplog'   RSS

2008-05-20
 
CVE-2008-2349

CWE-264
 

 
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.

 
2008-05-13
 
CVE-2008-2176

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in admin/category.php in Zomplog 3.8.2 allows remote attackers to inject arbitrary web script or HTML via the catname parameter.

 


Copyright 2024, cxsecurity.com

 

Back to Top