Vulnerabilities > CVE-2006-1616 - SQL-Injection vulnerability in Advanced Poll Advanced Poll 2.0.2

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
advanced-poll

Summary

Multiple SQL injection vulnerabilities in Advanced Poll 2.02 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to comments.php or (2) poll_id parameter to page.php.

Vulnerable Configurations

Part Description Count
Application
Advanced_Poll
1