Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts in /admin.
https://www.exploit-db.com/exploits/5616
https://exchange.xforce.ibmcloud.com/vulnerabilities/42427
http://www.securitytracker.com/id?1020035