PT-2009-2810 · Pollpro · Pollpro

The_0Nur-N0X

·

Publicado

2009-01-09

·

Atualizado

2017-08-08

·

CVE-2009-0112

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PollPro version 3.0
Description A cross-site request forgery issue exists, allowing remote attackers to create or modify accounts with administrative privileges. This is achieved by manipulating the username, password, and name parameters in the admin/agent edit.asp endpoint.
Recommendations For PollPro version 3.0, as a temporary workaround, consider restricting access to the admin/agent edit.asp endpoint until a patch is available. Avoid using the username, password, and name parameters in this endpoint until the issue is resolved.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-0112

Produtos afetados

Pollpro