Skip to main content

CWE archive

CWE-287 CVEs

Programmatic archive

4,482 CVEs tagged with CWE-2871,225 Critical, 1,565 High, 1,546 Medium, 144 Low, 2 Unrated.

CVE-2009-0138

Published Feb 13, 2009

servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify the system configuration.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6118

Published Feb 11, 2009

win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0461

Published Feb 10, 2009

Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0460

Published Feb 10, 2009

Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0492

Published Feb 10, 2009

Unspecified vulnerability in SimpleIrcBot before 1.0 Stable has unknown impact and attack vectors related to an "auth vulnerability."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6092

Published Feb 9, 2009

phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2427

Published Feb 6, 2009

The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0412

Published Feb 3, 2009

The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative acc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6045

Published Feb 3, 2009

Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6039

Published Feb 3, 2009

Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0280

Published Jan 27, 2009

Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5967

Published Jan 26, 2009

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calenda…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5964

Published Jan 23, 2009

Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0256

Published Jan 22, 2009

Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5945

Published Jan 22, 2009

Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provenance of this information is unk…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0030

Published Jan 21, 2009

A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0130

Published Jan 15, 2009

lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0129

Published Jan 15, 2009

libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0128

Published Jan 15, 2009

plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return value from the OpenSSL EVP_Ver…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0127

Published Jan 15, 2009

M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify functions, which might allow remot…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0126

Published Jan 15, 2009

The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0125

Published Jan 15, 2009

NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language library (aka libnasl) 2.2.11 does not properly check the ret…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,201-4,225 of 4,482 CVEsPage 169 of 180