add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by setting a cookie with admin=yes and login=admin.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Myblog |
Myblog |
* |
0.9.8 (including) |
References