MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a post to admin/settings.php that injects PHP code into settings.inc, which can then be executed via a direct request to index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mycms | Mycms | * | 0.9.8 (including) |