Leif M. Wrights Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Web_blog | Leif_m._wright | 3.5 (including) | 3.5 (including) |