MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php.
- http://securityreason.com/securityalert/2581
No PoCs found on GitHub currently.