Vulnerabilities (CVE)

Filtered by CWE-287
Total 3744 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6863 1 Xigla 1 Absolute Form Processor.net 2025-04-09 7.5 HIGH N/A
Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2008-1154 1 Cisco 4 Emergency Responder, Mobility Manager, Unified Communications Manager and 1 more 2025-04-09 10.0 HIGH N/A
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2009-2231 1 Mid.as 1 Midas 2025-04-09 7.5 HIGH N/A
MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record in a MIDAS cookie.
CVE-2007-2277 1 Plogger 1 Plogger 2025-04-09 7.5 HIGH N/A
Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
CVE-2009-1155 1 Cisco 2 Adaptive Security Appliance 5500, Pix 2025-04-09 7.8 HIGH N/A
Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2(4)27, 8.0 before 8.0(4)25, and 8.1 before 8.1(2)15, when AAA override-account-disable is entered in a general-attributes field, allow remote attackers to bypass authentication and establish a VPN session to an ASA device via unspecified vectors.
CVE-2009-2642 1 Desiscripts 1 Desi Short Url Script 2025-04-09 7.5 HIGH N/A
index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to 1 and the uid cookie to an integer value, as demonstrated by a value of 13.
CVE-2008-0351 1 Evilsentinel 1 Evilsentinel 2025-04-09 5.0 MEDIUM N/A
admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.
CVE-2008-3738 1 Spacetag 1 Lacoodast 2025-04-09 6.8 MEDIUM 9.1 CRITICAL
Session fixation vulnerability in SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
CVE-2009-1629 1 Antony Lesuisse 1 Ajaxterm 2025-04-09 6.8 MEDIUM N/A
ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it easier for remote attackers to (1) hijack a session or (2) cause a denial of service (session ID exhaustion) via a brute-force attack.
CVE-2008-5692 1 Ipswitch 1 Ws Ftp 2025-04-09 5.0 MEDIUM N/A
Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.
CVE-2008-6664 1 Yarck 1 Sh-news 2025-04-09 7.5 HIGH N/A
action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.
CVE-2008-3611 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-09 6.3 MEDIUM N/A
Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.
CVE-2008-6864 1 Xigla 1 Absolute Live Support .net 2025-04-09 7.5 HIGH N/A
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2009-1549 1 Agtc 1 Agtc Myshop 2025-04-09 7.5 HIGH N/A
AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto."
CVE-2008-6300 1 Gwm 1 Galatolo Webmanager 2025-04-09 7.5 HIGH N/A
Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-7041 1 Ajsquare 1 Aj Classifieds 2025-04-09 7.5 HIGH N/A
AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.
CVE-2008-6856 1 Xigla 1 Absolute News Manager.net 2025-04-09 7.5 HIGH N/A
Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2008-7006 1 Phpversion 1 Php Vx Guestbook 2025-04-09 5.0 MEDIUM N/A
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php.
CVE-2008-1938 1 Sony 1 Mylo Com 2 2025-04-09 6.4 MEDIUM N/A
Sony Mylo COM-2 Japanese model firmware before 1.002 does not properly verify web server SSL certificates, which allows remote attackers to obtain sensitive information and conduct spoofing attacks.
CVE-2009-4584 1 Dbmasters 1 Db Masters Multimedia Links Directory 2025-04-09 7.5 HIGH N/A
admin.php in dB Masters Multimedia Links Directory 3.1.3 allows remote attackers to bypass authentication and gain administrative access via a certain value of the admin_log cookie.