MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Myblog | Myblog | * | 0.9.8 (including) |