PHP SimpleNEWS and PHP SimpleNEWS MySQL contain a flaw that may allow a malicious user to bypass administrative authentication. The issue is due to the program only comparing the username supplied by the cookie when accessing the pages. By creating a cookie with the value of 'admin', the program does not compare the password supplied, allowing for administrative access.
Classification
Location:
Remote/Network Access Required
Attack Type:
Authentication Management
Impact:
Loss of Confidentiality
Exploit:
Exploit Unavailable
OSVDB:
Web Related
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.