Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PollHelper 权限许可和访问控制问题漏洞
Vulnerability Description
PollHelper是一款在网站内构建投票调查系统的工具PHP脚本。 PollHelper 存在权限许可和访问控制漏洞,该漏洞源于 PollHelper 将 poll.inc 存储在访问控制不足的 Web 根目录下,这允许远程攻击者通过直接请求下载包含用户凭据的数据库文件。
CVSS Information
N/A
Vulnerability Type
N/A