CVE-2002-0589
PVote < 1.9 - Unauthenticated Administrative Password Change via ch_info.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-0589. PoCs published by Daniel Nyström.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in PVote, allowing an attacker to change the administrative password without any prior authentication by sending a crafted HTTP request with specific URL parameters.
Description
PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in PVote, allowing an attacker to change the administrative password without any prior authentication by sending a crafted HTTP request with specific URL parameters.