Vulnerabilities (CVE)

Filtered by CWE-287
Total 3618 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-5576 1 Scssboard 1 Scssboard 2025-04-09 7.5 HIGH N/A
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.
CVE-2007-5752 1 Agtc Websolutions 1 Php-agtc Membership System 2025-04-09 7.5 HIGH N/A
adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via a modified form, as demonstrated by an account with admin (userlevel 4) privileges.
CVE-2008-6039 1 Bluepage 1 Bluepage Cms 2025-04-09 6.8 MEDIUM N/A
Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
CVE-2009-2088 1 Ibm 1 Websphere Application Server 2025-04-09 7.5 HIGH N/A
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single Sign-on (SSO) and disableSecurityPreInvokeOnFilters are configured, allows remote attackers to bypass authentication via a request for a "secure URL," related to a certain invokefilterscompatibility property.
CVE-2009-1384 2 Eyrie, Redhat 2 Pam-krb5, Enterprise Linux 2025-04-09 5.0 MEDIUM N/A
pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
CVE-2008-7041 1 Ajsquare 1 Aj Classifieds 2025-04-09 7.5 HIGH N/A
AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.
CVE-2007-6006 1 Testlink 1 Testlink 2025-04-09 10.0 HIGH N/A
TestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.
CVE-2008-6863 1 Xigla 1 Absolute Form Processor.net 2025-04-09 7.5 HIGH N/A
Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2009-2328 1 Max Kervin 1 Kervinet Forum 2025-04-09 7.5 HIGH N/A
admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitrary accounts and conduct SQL injection attacks via the del_user_id parameter.
CVE-2007-5085 1 Apache 1 Geronimo 2025-04-09 5.0 MEDIUM N/A
Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
CVE-2009-2071 1 Google 1 Chrome 2025-04-09 6.8 MEDIUM N/A
Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request.
CVE-2008-6919 1 Taskdriver 1 Taskdriver 2025-04-09 7.5 HIGH N/A
profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "fook!admin."
CVE-2009-0655 1 Lenovo 1 Veriface 2025-04-09 6.9 MEDIUM N/A
Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.
CVE-2008-6855 1 Xigla 1 Absolute News Feed 2025-04-09 7.5 HIGH N/A
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.
CVE-2008-5219 1 Videoscript 1 Videoscript 2025-04-09 7.5 HIGH N/A
The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.
CVE-2007-5913 1 Jean Charles 1 Jbc Explorer 2025-04-09 6.8 MEDIUM N/A
dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.php via the suppr parameter, and (2) re-create the auth.inc.php file with contents that specify a new account name and password for JBC Explorer via the login and password parameters.
CVE-2007-4419 1 Olate 1 Olatedownload 2025-04-09 9.3 HIGH N/A
Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area.
CVE-2008-5967 1 Phpicalendar 1 Phpicalendar 2025-04-09 7.5 HIGH N/A
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.
CVE-2008-6445 1 Yourplace 1 Yourplace 2025-04-09 7.5 HIGH N/A
Unspecified vulnerability in YourPlace before 1.0.1 has unknown impact and attack vectors, possibly related to improper authentication and the ability to upload arbitrary PHP code. NOTE: some of these details are obtained from third party information.
CVE-2009-0662 1 Plone 2 Plone, Plonepas 2025-04-09 6.0 MEDIUM N/A
The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.