Skip to main content

CWE archive

CWE-287 CVEs

Programmatic archive

4,685 CVEs tagged with CWE-2871,276 Critical, 1,671 High, 1,583 Medium, 153 Low, 2 Unrated.

CVE-2008-3375

Published Jul 30, 2008

The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3317

Published Jul 25, 2008

admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary search_cookie cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3318

Published Jul 25, 2008

admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary weblog_cookie cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3319

Published Jul 25, 2008

admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary links_cookie cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3320

Published Jul 25, 2008

admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary gbook_cookie cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3321

Published Jul 25, 2008

admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary uploader_cookie cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3322

Published Jul 25, 2008

admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary recipe_cookie cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3299

Published Jul 25, 2008

eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng cookie value to 1. NOTE: the provenance of this information…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3292

Published Jul 24, 2008

constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin cookie, as demonstrated via addpa…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3211

Published Jul 18, 2008

Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3203

Published Jul 17, 2008

js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id paramete…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2801

Published Jul 7, 2008

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary code via (1) injection of Jav…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3033

Published Jul 7, 2008

RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2920

Published Jun 30, 2008

admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete fi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2730

Published Jun 26, 2008

The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to byp…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2879

Published Jun 26, 2008

Benja CMS 0.1 does not require authentication for access to admin/, which allows remote attackers to add or delete a menu.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2833

Published Jun 24, 2008

admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2705

Published Jun 16, 2008

Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Enterprise Edition (DSEE), allows…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2406

Published Jun 4, 2008

The administration application server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to bypass authentication via direct requests on TCP port 51…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2524

Published Jun 3, 2008

BlogPHP 2.0 allows remote attackers to bypass authentication, and post (1) messages or (2) comments as an arbitrary user, via a modified blogphp_username field in a cookie.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2528

Published Jun 3, 2008

Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2516

Published Jun 3, 2008

pam_sm_authenticate in pam_pgsql.c in libpam-pgsql 0.6.3 does not properly consider operator precedence when evaluating the success of a pam_get_pass function call, which allows l…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,501-4,525 of 4,685 CVEsPage 181 of 188