Heap
20-05-08, 21:39
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2349)
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2349)