2008-09-15 15:00:00
mitre
PUBLISHED
admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie.