CVE-2007-5278
Last modified
CVE-2007-5278 is a vulnerability of currently unknown severity. Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct request to /upload and then retrieving individual files. NOTE: in a non-default configuration, the directory listing is denied, but filenames may be predicable.. EPSS estimates a 2.02% chance of exploitation in the next 30 days.
Description
Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct request to /upload and then retrieving individual files. NOTE: in a non-default configuration, the directory listing is denied, but filenames may be predicable.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zomplog | Zomplog | 3.8.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5278?
How severe is CVE-2007-5278?
How do I fix CVE-2007-5278?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5272SQL injection vulnerability in kategori.asp in Furkan Tastan…
- CVE-2007-5273Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2…
- CVE-2007-5274Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2…
- CVE-2007-5275The Adobe Macromedia Flash 9 plug-in allows remote attackers…
- CVE-2007-5276Opera 9 drops DNS pins based on failed connections to irrele…
- CVE-2007-5277Microsoft Internet Explorer 6 drops DNS pins based on failed…
- CVE-2007-5279Heap-based buffer overflow in ConeXware PowerArchiver before…
- CVE-2007-5280Multiple cross-site scripting (XSS) vulnerabilities in messa…
- CVE-2007-5281The Java Secure Socket Extension (JSSE) in the Hitachi Cosmi…
- CVE-2007-5282Hitachi Cosminexus Agent 03-00 through 03-05, and Cosminexus…
- CVE-2007-5283The TSC Domain Manager in Hitachi TPBroker Object Transactio…
- CVE-2007-5284Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
Are you affected by CVE-2007-5278?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
