nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_edit.php, (2) template_edit.php, or (3) survey_edit.php in admin/.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nabopoll | Nabocorp | 1.1 (including) | 1.1 (including) |
Nabopoll | Nabocorp | 1.2 (including) | 1.2 (including) |