CVE Vulnerabilities

CVE-2002-0588

Published: Jun 18, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.

Affected Software

Name Vendor Start Version End Version
Pvote Steve_korbett 1.0 (including) 1.0 (including)
Pvote Steve_korbett 1.0a (including) 1.0a (including)
Pvote Steve_korbett 1.0b (including) 1.0b (including)
Pvote Steve_korbett 1.5 (including) 1.5 (including)

References