vendor:
Advanced Poll
by:
SecurityFocus
5
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: Advanced Poll
Affected Version From: 2
Affected Version To: 2
Patch Exists: YES
Related CWE: CVE-2002-1490
CPE: a:php:advanced_poll
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2002
Information Disclosure Vulnerability in Advanced Poll
Advanced Poll is vulnerable to an information disclosure vulnerability. A remote user can access privileged information by accessing the info.php files located in the poll_dir/db/ and poll_dir/textfile/ directories. This information can be used to further attack the host and its users.
Mitigation:
Upgrade to the latest version of Advanced Poll.