CVE-2008-2349: High severity simplog vulnerability
Published May 20, 2008
·Updated
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.
Affected Software
1 affected component
Zomp Zomplog<=3.8.2
Event History
May 20, 2008
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2349?
CVE-2008-2349 is considered a high severity vulnerability due to its potential to lead to unauthorized administrative access.
2
How do I fix CVE-2008-2349?
To fix CVE-2008-2349, update Zomplog to version 3.8.3 or later where this vulnerability has been addressed.
3
What kind of vulnerabilities does CVE-2008-2349 exploit?
CVE-2008-2349 exploits improper authorization mechanisms in Zomplog allowing attackers to create administrative accounts.
4
Who is affected by CVE-2008-2349?
CVE-2008-2349 affects all Zomplog versions prior to 3.8.3.
5
What is the impact of CVE-2008-2349 on users?
The impact of CVE-2008-2349 on users can be significant as it allows attackers to gain full administrative control over the Zomplog installation.