"Current question" field allows for code injection, allowing us to force
all users browsing the poll to view an XSS or browser exploit.
File Upload
-----------
admin.php?A=potd
The "picture of the day" manager allows for further images to be
uploaded, but does not check for image validity. Although a phpshell
cannot be executed through this method, a source may be uploaded for
inclusion in further attacks, possibly an LFI somewhere on the server.
Maksymilian Arciemowicz discovered a Integer Overflow
vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.