2015-05-01 10:00:00
jpcert
PUBLISHED
EasyCTF before 1.4 does not validate the session ID, which allows remote attackers to obtain access via a crafted HTTP request.