Description - Auth Bypass in PHP SimpleNEWS, PHP SimpleNEWS MySQL

Unauthorized Data Modification found in PHP SimpleNEWS, PHP SimpleNEWS MySQL script.

Exploit
Available
Solution
Available

Vulnerabe script: admin.php

To check if administrator logged in script use only one cookie variable: admin and dont make password comparison.

Order Source Code Analysis made by eVuln team

Check your site or web application by source code test of your website made by eVuln team.The task will be done by experts in web security.