A vulnerability has been identified in various MRCGIGUY products, which could be exploited by remote attackers to bypass security restrictions. This issue is caused by a design error in the administrative interface that relies on cookie data to authenticate users, which could be exploited by attackers to gain unauthorized administrative access to a vulnerable web application via a specially crafted cookie.
Vulnerable Products
Vulnerable Software: MRCGIGUY ClickBank Directory version 1.0.1 and priorMRCGIGUY Hot Links SQL version 3.2.0 and priorMRCGIGUY Amazon Directory version 1.0 and priorMRCGIGUY Amazon Directory version 2.0 and priorMRCGIGUY Message Box version 1.0 and priorMRCGIGUY Message Box version 1.0 and priorMRCGIGUY Ultimate Profit Portal version 1.0.1 and priorMRCGIGUY SimpLISTic SQL version 2.0.0 and priorMRCGIGUY Top Sites version 1.0.0 and prior