PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password.
| Software | From | Fixed in |
|---|---|---|
| steve_korbett / pvote | 1.0 | 1.0.x |
| steve_korbett / pvote | 1.0b | 1.0b.x |
| steve_korbett / pvote | 1.5 | 1.5.x |
| steve_korbett / pvote | 1.0a | 1.0a.x |