Format string bugs and insufficient username checks allows administrative access.
vulners.com/securityvulns/securityvulns:doc:3545