vendor:
Advanced Poll Script
by:
Sid3^effects
N/A
CVSS
N/A
XSS and Authentication bypass
CWE
Product Name: Advanced Poll Script
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
Unknown
XSS and Authentication bypass in Advanced Poll Script
The Advanced Poll script has an authentication bypass vulnerability in both the admin login and user login. It can be exploited by using the payload ' or 1=1 or ''=' in both the login and password fields. Additionally, an XSS vulnerability is also found in the search field.
Mitigation:
Unknown