index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpusuario cookie composed of an initial sysop: string, an arbitrary password field, and a final :sysop:0 string.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Adnforum | Adnforum | * | 1.0b (including) |