KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts.Referenceshttp://www.osvdb.org/44257https://exchange.xforce.ibmcloud.com/vulnerabilities/41747http://secunia.com/advisories/29716https://www.exploit-db.com/exploits/5418