Leif M. Wrights Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Web_blog | Leif_m._wright | 3.5 (including) | 3.5 (including) |