"value":"CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator privileges via a request with (1) login.php or (2) password_forgotten.php appended as the PATH_INFO, which bypasses a check that uses PHP_SELF, which is not properly handled by (a) includes/application_top.php and (b) admin/includes/application_top.php, as exploited in the wild in 2009."
},
{
"lang":"es",
"value":"CRE Loaded anterior a v6.2.14, y posiblemente otras versiones anteriores a v6.3.x, permite a atacantes remotos evitar la autenticaci\u00f3n y obtener privilegios de administrador a trav\u00e9s de una solicitud con (1)login.php o (2) password_forgotten.php a\u00f1adidas como PATH_INFO, que pasa por alto un control que usa PHP_SELF, que no se maneja de forma adecuada por (a) include/application_top.php y (b) /includes/application_top.php, como los explotados en 2009."