Skip to main content

CWE archive

CWE-287 CVEs

Programmatic archive

4,483 CVEs tagged with CWE-2871,225 Critical, 1,565 High, 1,547 Medium, 144 Low, 2 Unrated.

CVE-2009-1596

Published May 11, 2009

Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated us…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1595

Published May 11, 2009

The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts vi…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1587

Published May 7, 2009

index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, login_name, user_id, and user_t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1549

Published May 6, 2009

AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1504

Published May 1, 2009

Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "lvl=1&userid=1."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1489

Published Apr 29, 2009

includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6763

Published Apr 28, 2009

login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0662

Published Apr 23, 2009

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the id…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6743

Published Apr 22, 2009

RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct req…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6739

Published Apr 21, 2009

Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6738

Published Apr 21, 2009

MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6723

Published Apr 14, 2009

TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cookie to Administrator.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6719

Published Apr 13, 2009

U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an uns…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6718

Published Apr 13, 2009

U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6717

Published Apr 13, 2009

U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6716

Published Apr 13, 2009

homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to have an unspecified impact via a direct…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6714

Published Apr 10, 2009

admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by setting the xecms_username cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6664

Published Apr 8, 2009

action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6581

Published Apr 2, 2009

login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1570

Published Mar 31, 2009

The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, wh…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-6569

Published Mar 31, 2009

Session fixation vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack web sessions via the session ID in the login page.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0892

Published Mar 31, 2009

The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessions in "specific scenarios" re…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,151-4,175 of 4,483 CVEsPage 167 of 180