LinPHA contains a flaw that will allow an attacker to bypass authentication. The problem is due to a input validation error within the 'session.php' script and will allow an attacker to inject specially crafted session cookies prior to loading admin.php allowing the attacker to bypass authentication.
Classification
Location:
Remote / Network Access
Attack Type:
Authentication Management,
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
Solution
Upgrade to version 1.13 of session.php or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds. The fix is available via CVS from the vendor.