default.asp in ASP-Nuke Community 1.5 and earlier allows remote attackers to gain privileges by setting certain pseudo cookie values.
| Software | From | Fixed in |
|---|---|---|
| asp-nuke / asp-nuke | rc3 | rc3.x |
| asp-nuke / asp-nuke | rc2 | rc2.x |
| asp-nuke / asp-nuke | 1.3 | 1.3.x |
| asp-nuke / asp-nuke | 1.0 | 1.0.x |
| asp-nuke / asp-nuke | 1.5 | 1.5.x |
| asp-nuke / asp-nuke | rc1 | rc1.x |
| asp-nuke / asp-nuke | 1.2 | 1.2.x |