nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_edit.php, (2) template_edit.php, or (3) survey_edit.php in admin/.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Nabopoll | Nabocorp | 1.1 (including) | 1.1 (including) |
| Nabopoll | Nabocorp | 1.2 (including) | 1.2 (including) |