CVE-2002-0588 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 6.6% (pctl 94)
Patch early
A public exploit exists.
Description
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 6.61% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-06-18 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| steve korbett | pvote |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PVote 1.0/1.5 - Poll Content Manipulation | 2002-04-18 |
References
- http://online.securityfocus.com/archive/1/268231
- http://orbit-net.net:8001/php/pvote/
- http://www.iss.net/security_center/static/8877.php
- http://www.securityfocus.com/bid/4540
- http://online.securityfocus.com/archive/1/268231
- http://orbit-net.net:8001/php/pvote/
- http://www.iss.net/security_center/static/8877.php
- http://www.securityfocus.com/bid/4540
→ the Explorer · watch your stack · NVD