PVote Unauthorized Administrative Password Change Vulnerability
BID:4541
Info
PVote Unauthorized Administrative Password Change Vulnerability
| Bugtraq ID: | 4541 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0589 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 18 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovery of this issue is credited to Daniel Nyström <[email protected]>. |
| Vulnerable: |
PVote PVote 1.5 PVote PVote 1.0 b PVote PVote 1.0 a PVote PVote 1.0 |
| Not Vulnerable: |
PVote PVote 1.9 |
Discussion
PVote Unauthorized Administrative Password Change Vulnerability
PVote is a web voting system written in PHP. It will run on most Unix and Linux variants as well as Microsoft Windows operating systems.
It is possible to change the administrative password by submitting a malicious web request containing the appropriate values for the URL parameters. No authentication credentials are required.
PVote is a web voting system written in PHP. It will run on most Unix and Linux variants as well as Microsoft Windows operating systems.
It is possible to change the administrative password by submitting a malicious web request containing the appropriate values for the URL parameters. No authentication credentials are required.
Solution / Fix
PVote Unauthorized Administrative Password Change Vulnerability
Solution:
This vulnerability has been addressed in version 1.9 of PVote. Those affected by this vulnerability are advised to upgrade.
PVote PVote 1.0 a
PVote PVote 1.0 b
PVote PVote 1.0
PVote PVote 1.5
Solution:
This vulnerability has been addressed in version 1.9 of PVote. Those affected by this vulnerability are advised to upgrade.
PVote PVote 1.0 a
-
PVote PVote 1.9
http://orbit-net.net:8001/php/pvote/pvote.zip
PVote PVote 1.0 b
-
PVote PVote 1.9
http://orbit-net.net:8001/php/pvote/pvote.zip
PVote PVote 1.0
-
PVote PVote 1.9
http://orbit-net.net:8001/php/pvote/pvote.zip
PVote PVote 1.5
-
PVote PVote 1.9
http://orbit-net.net:8001/php/pvote/pvote.zip