7.5
CVSSv2

CVE-2007-0873

Published: 12/02/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

nabopoll 1.1.2 allows remote malicious users to bypass authentication and access certain administrative functionality via a direct request for (1) config_edit.php, (2) template_edit.php, or (3) survey_edit.php in admin/.

Vulnerable Product Search on Vulmon Subscribe to Product

nabocorp nabopoll 1.1

nabocorp nabopoll 1.2

Exploits

* nabopoll 112 sensitive file (admin without password) * By : sn0oPy * Risk : high * site : nabocorpcom/ * Dork : inurl:"nabopoll/" * exploit : acces without password to : target/nabopoll/admin/config_editphp target/nabopoll/admin/template_editphp target/nabopoll/admin/survey_editphp * contact : sn0oPy (at) ...