CVE

Id
4979  
CVE No.
CVE-2002-0588  
Status
Candidate  
Description
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.  
Phase
Proposed (20020611)  
Votes
ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall  
Comments