PT-2009-2810 · Pollpro · Pollpro

The_0Nur-N0X

·

Published

2009-01-09

·

Updated

2017-08-08

·

CVE-2009-0112

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PollPro version 3.0
Description A cross-site request forgery issue exists, allowing remote attackers to create or modify accounts with administrative privileges. This is achieved by manipulating the username, password, and name parameters in the admin/agent edit.asp endpoint.
Recommendations For PollPro version 3.0, as a temporary workaround, consider restricting access to the admin/agent edit.asp endpoint until a patch is available. Avoid using the username, password, and name parameters in this endpoint until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0112

Affected Products

Pollpro