PT-2000-1976 · Poll It · Poll It

Published

2000-12-11

·

Updated

2017-10-10

·

CVE-2000-1068

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Poll It version 2.0
Description The issue allows remote attackers to execute arbitrary commands. This is achieved by injecting shell metacharacters into the poll options parameter.
Recommendations For Poll It version 2.0, consider restricting access to the pollit.cgi script until a patch is available, or avoid using the poll options parameter in a way that could allow shell metacharacter injection.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-1068

Affected Products

Poll It