Phase:Advanced Poll before 1.61, when using a flat file database, allows remote attackers to gain privileges by setting the logged_in parameter.
ReferencesCERT-VN:VU#140723 | URL:http://www.kb.cert.org/vuls/id/140723 | SECTRACK:1002516 | URL:http://securitytracker.com/id?1002516 | XF:advancedpoll-php-admin-access(7861) | URL:http://xforce.iss.net/xforce/xfdb/7861
Votes:Assigned (Sunday, March 20, 2005)
Comments:None (candidate not yet proposed)
F7: