Vulnerable Systems:
*Google Authenticator Login Module for Drupal 7.x-1.2
Google Authenticator Login Module for Drupal contains a flaw that is triggered when multi-factor authentication is enabled for an account, but a token has not been specified for that account. This may allow a remote attacker to bypass authentication and login to a user's account by simply supplying the account name and no password.