PT-2006-5438 · Unknown · Amazing Little Poll+1

Alperen

+1

·

Publicado

2006-09-09

·

Atualizado

2018-10-17

·

CVE-2006-4653

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Amazing Little Poll and Amazing Little Picture Poll (affected versions not specified)
Description The issue allows remote attackers to read the admin password via a direct request for the lp settings file, which can be either lp settings.inc or lp settings.php, due to insufficient access control. This occurs because sensitive information is stored under the web root.
Recommendations For Amazing Little Poll and Amazing Little Picture Poll, consider restricting access to the lp settings file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4653

Produtos afetados

Amazing Little Picture Poll
Amazing Little Poll