Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the poll_id parameter, which is supplied to an eval function call, a different vulnerability type than CVE-2005-4632.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2007/0300 | vdb entry |
http://osvdb.org/31606 | vdb entry |
https://www.exploit-db.com/exploits/3180 | exploit |
http://secunia.com/advisories/23834 | third party advisory |