redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.
- http://securityreason.com/securityalert/4804
- https://www.exploit-db.com/exploits/6729
No PoCs found on GitHub currently.