Directory Traversal Vulnerability in Zomplog 3.8
CVE-2007-2157

Currently unrated

Key Information:

Vendor

Zomplog

Status
Vendor
CVE Published:
19 April 2007

What is CVE-2007-2157?

A directory traversal vulnerability exists in Zomplog 3.8 that allows remote attackers to exploit the upload/force_download.php script. By manipulating the file parameter, attackers can traverse the directory structure using '../' sequences, enabling them to read arbitrary files on the server. This can lead to unauthorized access to sensitive information and potential further exploitation.

References

EPSS Score

10% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2007-2157 : Directory Traversal Vulnerability in Zomplog 3.8