PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pvote | Steve_korbett | 1.0 (including) | 1.0 (including) |
Pvote | Steve_korbett | 1.0a (including) | 1.0a (including) |
Pvote | Steve_korbett | 1.0b (including) | 1.0b (including) |
Pvote | Steve_korbett | 1.5 (including) | 1.5 (including) |