Skip to main content

CWE archive

CWE-287 CVEs

Programmatic archive

4,511 CVEs tagged with CWE-2871,237 Critical, 1,581 High, 1,547 Medium, 144 Low, 2 Unrated.

CVE-2008-6857

Published Jul 14, 2009

Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6856

Published Jul 14, 2009

Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6855

Published Jul 14, 2009

Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6854

Published Jul 14, 2009

Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2334

Published Jul 10, 2009

wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2382

Published Jul 8, 2009

admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin cookie to LOGGEDIN.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2328

Published Jul 5, 2009

admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitrary accounts and conduct SQL in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2257

Published Jun 30, 2009

The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to (1) gateway/commands/saveconf…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2255

Published Jun 30, 2009

Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to execute arbitrary code by uploadi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2233

Published Jun 26, 2009

The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the awse_logged cookie to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2231

Published Jun 26, 2009

MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record in a MIDAS cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2168

Published Jun 22, 2009

cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are incorrect, which allows remo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2159

Published Jun 22, 2009

backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2117

Published Jun 18, 2009

uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1390

Published Jun 16, 2009

Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of v…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2072

Published Jun 15, 2009

Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to spoof an arbitrary https site b…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2071

Published Jun 15, 2009

Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2070

Published Jun 15, 2009

Opera displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2069

Published Jun 15, 2009

Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attack…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2068

Published Jun 15, 2009

Google Chrome detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an htt…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2067

Published Jun 15, 2009

Opera detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site'…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2066

Published Jun 15, 2009

Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an http…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2065

Published Jun 15, 2009

Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,126-4,150 of 4,511 CVEsPage 166 of 181