PT-2006-5437 · Amazing Little · Amazing Little Picture Poll+1
Alperen
+1
·
Published
2006-09-09
·
Updated
2018-10-17
·
CVE-2006-4652
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Amazing Little Poll versions (affected versions not specified)
Amazing Little Picture Poll versions (affected versions not specified)
Description
The issue concerns default passwords in the software, allowing remote attackers to create new polls by entering these default credentials. Specifically, the default password "dsapoll" can be used to access the system via the lp admin.php endpoint, enabling unauthorized creation of polls.
Recommendations
For Amazing Little Poll, change the default password "dsapoll" to a unique and secure password.
For Amazing Little Picture Poll, change the default password "dsapoll" to a unique and secure password.
As a temporary workaround, consider restricting access to the lp admin.php endpoint until secure passwords are implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Amazing Little Picture Poll
Amazing Little Poll