a) SQL Injection
Variable $HTTP_POST_VARS[username] isn't properly sanitized before being
used in a SQL query. This can be used to make any SQL query by injecting
arbitrary SQL code.
Condition: magic_quotes_gpc - off
b) Cookie based authentication
check.php script dont make password comparisson when identifying user by
cookies
Multiple Cross-Site Scripting & Multiple SQL Injections vulnerabilities are
present in administrator's control panel.
--------------Exploit----------------------
Available at: http://evuln.com/vulns/61/exploit.html
--------------Solution---------------------
No Patch available.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.