PT-2006-3203 · Codemunkyx · Codemunkyx Simple Poll
Published
2006-05-05
·
Updated
2018-10-18
·
CVE-2006-2235
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CodeMunkyX (aka free-php.net) Simple Poll version 1.0
Description
The issue allows remote attackers to gain administrative privileges by appending
/admin/ to the top-level URI of the application when authentication is not required for the admin directory.Recommendations
For CodeMunkyX (aka free-php.net) Simple Poll version 1.0, ensure that authentication is required for the admin directory to prevent unauthorized access.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Codemunkyx Simple Poll