Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) right_cookie to "1," and (3) id_cookie to "1."Referenceshttps://www.exploit-db.com/exploits/6968https://exchange.xforce.ibmcloud.com/vulnerabilities/46287http://secunia.com/advisories/32517http://www.securityfocus.com/bid/32083