Vulnerabilities (CVE)

Filtered by CWE-287
Total 3679 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-0460 1 Wholehogsoftware 1 Ware Support 2025-04-09 7.5 HIGH N/A
Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.
CVE-2009-3158 1 Carsten Wulff 1 Simplephpweb 2025-04-09 7.5 HIGH N/A
admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via unknown vectors. NOTE: some of these details are obtained from third party information.
CVE-2009-3422 1 Zenas 1 Paoliber 2025-04-09 6.8 MEDIUM N/A
login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.
CVE-2008-0377 1 News 1 Micronews 2025-04-09 10.0 HIGH N/A
MicroNews allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin.php.
CVE-2009-4095 1 Companionway 1 Myphile 2025-04-09 7.5 HIGH N/A
myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party information.
CVE-2009-0021 1 Ntp 1 Ntp 2025-04-09 5.0 MEDIUM N/A
NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
CVE-2009-4409 1 Iij 1 Seil\/b1 2025-04-09 2.6 LOW N/A
The (1) CHAP and (2) MS-CHAP-V2 authentication capabilities in the PPP Access Concentrator (PPPAC) function in Internet Initiative Japan SEIL/B1 firmware 1.00 through 2.52 use the same challenge for each authentication attempt, which allows remote attackers to bypass authentication via a replay attack.
CVE-2009-2328 1 Max Kervin 1 Kervinet Forum 2025-04-09 7.5 HIGH N/A
admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitrary accounts and conduct SQL injection attacks via the del_user_id parameter.
CVE-2008-6861 1 Xigla 1 Absolute Newsletter 2025-04-09 7.5 HIGH N/A
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2008-6581 1 Phpaddedit 1 Phpaddedit 2025-04-09 7.5 HIGH N/A
login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.
CVE-2008-3319 1 Maian 1 Links 2025-04-09 7.5 HIGH N/A
admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary links_cookie cookie.
CVE-2009-2863 1 Cisco 1 Ios 2025-04-09 7.1 HIGH N/A
Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227.
CVE-2008-3292 1 Ezwebalbum 1 Ezwebalbum 2025-04-09 6.4 MEDIUM N/A
constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin cookie, as demonstrated via addpage.php.
CVE-2009-1638 1 T-dreams 1 Job Career Package 2025-04-09 7.5 HIGH N/A
Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin cookie to Login.
CVE-2008-6717 1 Uochm 1 Signup 2025-04-09 7.5 HIGH N/A
U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) adminstart.php, (2) admineventtype.php, (3) admineventdetails.php, (4) admineventlist.php, (5) adminuserslist.php, (6) adminleaderslist.php, (7) admindatabase.php, and possibly (8) index.php.
CVE-2007-5391 1 Hp 1 Select Identity 2025-04-09 10.0 HIGH N/A
Unspecified vulnerability in HP Select Identity 4.01 through 4.01.010 and 4.10 through 4.13.001 allows remote attackers to obtain unspecified access via unknown vectors.
CVE-2008-3375 1 Jamroom 1 Jamroom 2025-04-09 7.5 HIGH N/A
The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie cookie.
CVE-2008-4721 1 Php Jabbers 1 Post Comment 2025-04-09 7.5 HIGH N/A
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged."
CVE-2008-7008 1 Hyperstop 1 Web Host Directory 2025-04-09 5.0 MEDIUM N/A
HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/db.
CVE-2008-0407 1 Hfs 1 Http File Server 2025-04-09 5.0 MEDIUM N/A
HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request.