INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/167172 | mailing list patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6202 | vdb entry |