Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the poll_id parameter, which is supplied to an eval function call, a different vulnerability type than CVE-2005-4632.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vote_pro | Vote_pro | * | 4.0 (including) |