7.5
CVSSv2

CVE-2002-0589

Published: 18/06/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PVote prior to 1.9 allows remote malicious users to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password.

Vulnerable Product Search on Vulmon Subscribe to Product

steve korbett pvote 1.0a

steve korbett pvote 1.0b

steve korbett pvote 1.5

steve korbett pvote 1.0

Exploits

source: wwwsecurityfocuscom/bid/4541/info PVote is a web voting system written in PHP It will run on most Unix and Linux variants as well as Microsoft Windows operating systems It is possible to change the administrative password by submitting a malicious web request containing the appropriate values for the URL parameters No authenti ...