oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel via a 0 in the uid parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openjournal | Openjournal | 2.0_3 | 2.0_3 |
Openjournal | Openjournal | 2.0_4 | 2.0_4 |
Openjournal | Openjournal | 2.0_1 | 2.0_1 |
Openjournal | Openjournal | 2.0_5 | 2.0_5 |
Openjournal | Openjournal | 2.0_2 | 2.0_2 |
Openjournal | Openjournal | 2.0 | 2.0 |