CVE

Id
4980  
CVE No.
CVE-2002-0589  
Status
Candidate  
Description
PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password.  
Phase
Proposed (20020611)  
Votes
ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall  
Comments