Zomplog Index.PHP Local File Include Vulnerability
BID:22157
Info
Zomplog Index.PHP Local File Include Vulnerability
| Bugtraq ID: | 22157 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-1524 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2007 12:00AM |
| Updated: | May 12 2015 07:35PM |
| Credit: | Bl0od3r is credited with discovering this vulnerability. |
| Vulnerable: |
Zomplog Zomplog 3.7.6 Zomplog Zomplog 3.4 Zomplog Zomplog 3.3 |
| Not Vulnerable: | |
Discussion
Zomplog Index.PHP Local File Include Vulnerability
Zomplog is prone to a local file-include vulnerability because the application fails to sanitize user-supplied input.
An attacker can exploit this issue by injecting malicious code into webserver log files and executing it in the context of the user running the webserver process; other attacks are also possible.
Zomplog is prone to a local file-include vulnerability because the application fails to sanitize user-supplied input.
An attacker can exploit this issue by injecting malicious code into webserver log files and executing it in the context of the user running the webserver process; other attacks are also possible.
Exploit / POC
Zomplog Index.PHP Local File Include Vulnerability
Attackers may exploit this issue through a browser.
The following exploit code is available:
Attackers may exploit this issue through a browser.
The following exploit code is available: