FireFly, you are wrong, if you have cookies set you can login to admin control panel, by adding going to /admin/index.php?loginusername=xxx it doesn't matter what xxx is, it can be anything, doesn't have to be a user.
I verified by dumping everything from the session table in myphpadmin and then logging in. It doesn't work if you have cleared your cookies, so you still need to find a board with html enabled anywhere to steal cookies from admins. Btw, if you steal cookies you can still change email and then change password to get admin cp access, so for the endevouring hacker nothing changes