Security Advisory
CVE-2006-4427
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
index.php in eFiction before 2.0.7 allows remote attackers to bypass authentication and gain privileges by setting the (1) adminloggedin, (2) loggedin, and (3) level parameters to "1".