PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pvote | Steve_korbett | 1.0 (including) | 1.0 (including) |
Pvote | Steve_korbett | 1.0a (including) | 1.0a (including) |
Pvote | Steve_korbett | 1.0b (including) | 1.0b (including) |
Pvote | Steve_korbett | 1.5 (including) | 1.5 (including) |