Skip to main content

CWE archive

CWE-287 CVEs

Programmatic archive

4,482 CVEs tagged with CWE-2871,225 Critical, 1,565 High, 1,546 Medium, 144 Low, 2 Unrated.

CVE-2009-0591

Published Mar 27, 2009

The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote att…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-6523

Published Mar 25, 2009

auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE: this can be leveraged with…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0891

Published Mar 25, 2009

The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33)…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1050

Published Mar 24, 2009

Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYourself cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6455

Published Mar 13, 2009

Session fixation vulnerability in Edikon phpShop 0.8.1 allows remote attackers to hijack web sessions via unspecified vectors. NOTE: the provenance of this information is unknown…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0864

Published Mar 10, 2009

S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0853

Published Mar 9, 2009

login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via special characters in the User…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6445

Published Mar 9, 2009

Unspecified vulnerability in YourPlace before 1.0.1 has unknown impact and attack vectors, possibly related to improper authentication and the ability to upload arbitrary PHP code…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6411

Published Mar 6, 2009

Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6307

Published Feb 26, 2009

E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0614

Published Feb 26, 2009

Unspecified vulnerability in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) (aka 7.0 MR1) allows remote at…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6300

Published Feb 26, 2009

Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6269

Published Feb 25, 2009

Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0440

Published Feb 22, 2009

IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authenticated users to submit a cra…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0655

Published Feb 20, 2009

Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0653

Published Feb 20, 2009

OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0642

Published Feb 20, 2009

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully presen…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6162

Published Feb 20, 2009

Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNick cookie to admin.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6143

Published Feb 16, 2009

OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6131

Published Feb 13, 2009

Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6128

Published Feb 13, 2009

Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0360

Published Feb 13, 2009

Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privilege…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0362

Published Feb 13, 2009

filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (forced authentication failures) via a crafte…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,176-4,200 of 4,482 CVEsPage 168 of 180