5
CVSSv2

CVE-2002-0588

Published: 18/06/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

PVote prior to 1.9 does not authenticate users for restricted operations, which allows remote malicious users to add or delete polls by modifying parameters to (1) add.php or (2) del.php.

Vulnerable Product Search on Vulmon Subscribe to Product

steve korbett pvote 1.0b

steve korbett pvote 1.0

steve korbett pvote 1.0a

steve korbett pvote 1.5

Exploits

source: wwwsecurityfocuscom/bid/4540/info PVote is a web voting system written in PHP It will run on most Unix and Linux variants as well as Microsoft Windows operating systems It is possible for a remote attacker to add/delete web polls just by manipulating the values of URL parameters ADD A POLL: target/pvote/addphp?quest ...