PT-2003-2132 · Unknown · Advanced Poll
Published
2003-12-31
·
Updated
2017-07-11
·
CVE-2003-1180
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Advanced Poll version 2.0.2
Description
A directory traversal issue allows remote attackers to read arbitrary files or inject arbitrary local PHP files via .. sequences in the
base path or pollvars[lang] parameters to various admin files, including "index.php", "admin tpl new.php", "admin tpl misc new.php", "admin templates misc.php", "admin templates.php", "admin stats.php", "admin settings.php", "admin preview.php", "admin password.php", "admin logout.php", "admin license.php", "admin help.php", "admin embed.php", "admin edit.php", or "admin comment.php".Recommendations
For Advanced Poll version 2.0.2, consider restricting access to the vulnerable admin files until a patch is available. As a temporary workaround, avoid using the
base path and pollvars[lang] parameters in the affected admin files. Restrict access to the admin directory to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Advanced Poll