Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie.
| Software | From | Fixed in |
|---|---|---|
| demarc_security / puresecure | 1.0.5_for_unix | 1.0.5_for_unix.x |
| demarc_security / puresecure | 1.0.5_for_windows | 1.0.5_for_windows.x |