CVE detail
CVE-2007-5278 — CVE-2007-5278
Published 2007-10-08 · Modified 2026-06-16 · Vendor zomplog · Product zomplog · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0202
EPSS probability
exploitation probability, 30d
79.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct request to /upload and then retrieving individual files. NOTE: in a non-default configuration, the directory listing is denied, but filenames may be predicable.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References