Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PVote Poll投票内容可操作漏洞
Vulnerability Description
Pvote是一款由PHP编写的WEB投票系统,可运行在Linux和Unix操作系统下,也运行在Microsoft Windows操作系统下。 Pvote对用户输入缺少正确的检查,可导致远程攻击者可以任意增减内容。 攻击者可以通过操作提交给add.php和del.php脚本中参数的内容,就可以任意删除,或者增加投票内容。
CVSS Information
N/A
Vulnerability Type
N/A