The 'newsadmin.asp' script grants administrative privileges to the remote
user if a certain cookie is set.
A remote user can set a cookie named 'loggedIn' with a value of 'xY1zZoPQ'
to gain administrative privileges.
Solution:
--------------------
No patch`s released yet by vendor.
Original Advisory:
--------------------
http://www.kapda.ir/advisory-332.html
Credit :
--------------------
FarhadKey of KAPDA
farhadkey [at} kapda <d0t> net
Kapda - Security Science Researchers Insitute of Iran
http://www.KAPDA.ir
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.