login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Phpwishlist | Phpwishlist | 0.1.9 (including) | 0.1.9 (including) |
| Phpwishlist | Phpwishlist | 0.1.10 (including) | 0.1.10 (including) |
| Phpwishlist | Phpwishlist | 0.1.11 (including) | 0.1.11 (including) |
| Phpwishlist | Phpwishlist | 0.1.12 (including) | 0.1.12 (including) |
| Phpwishlist | Phpwishlist | 0.1.13 (including) | 0.1.13 (including) |
| Phpwishlist | Phpwishlist | 0.1.14 (including) | 0.1.14 (including) |