peter bassill · operator
$ cve CVE-2002-0588 JSON

CVE-2002-0588 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 6.6% (pctl 94)

Patch early

A public exploit exists.

Description

PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS6.61% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2002-06-18
Last modified2026-06-16

Affected (1)

VendorProduct
steve korbettpvote

Public exploits

SourceTitleDate
exploit-dbPVote 1.0/1.5 - Poll Content Manipulation2002-04-18

References

→ the Explorer  ·  watch your stack  ·  NVD