PT-2009-2514 · Aj Square · Aj Square Free Polling Script

G4N0K

·

Publicado

2009-08-24

·

Atualizado

2017-09-29

·

CVE-2008-7045

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions AJ Square Free Polling Script (AJPoll) Database version
Description The issue allows remote attackers to bypass authentication and reset poll votes by making a direct request to "admin/resetvote.php".
Recommendations For AJ Square Free Polling Script (AJPoll) Database version, restrict access to the "admin/resetvote.php" endpoint to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-7045

Produtos afetados

Aj Square Free Polling Script