vendor:
zomplog
by:
Mirabbas Agalarov
7.5
CVSS
HIGH
RCE
78
CWE
Product Name: zomplog
Affected Version From: 3.9
Affected Version To: 3.9
Patch Exists: NO
Related CWE:
CPE: zomplog
Platforms Tested: Linux
2023
zomplog 3.9 – Remote Code Execution (RCE)
This exploit allows an attacker to execute arbitrary code remotely in zomplog version 3.9. By manipulating the 'html' parameter, the attacker can inject PHP code to read the '/etc/passwd' file. This allows unauthorized access to sensitive system information.
Mitigation:
Update to a patched version of zomplog to prevent remote code execution attacks.