PT-2006-5438 · Unknown · Amazing Little Poll+1
Alperen
+1
·
Published
2006-09-09
·
Updated
2018-10-17
·
CVE-2006-4653
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Amazing Little Poll and Amazing Little Picture Poll (affected versions not specified)
Description
The issue allows remote attackers to read the admin password via a direct request for the
lp settings file, which can be either lp settings.inc or lp settings.php, due to insufficient access control. This occurs because sensitive information is stored under the web root.Recommendations
For Amazing Little Poll and Amazing Little Picture Poll, consider restricting access to the
lp settings file to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Amazing Little Picture Poll
Amazing Little Poll