Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Php Vx Guestbook MEDIUM 5.0
CVE-2008-7006EPSS 7%

Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backu…

No fix yet
Fix from $1,600 2009-08-19
Php Vx Guestbook HIGH 7.5
CVE-2008-7007

Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name and (2) admi…

No fix yet
Fix from $1,950 2009-08-19
Web Host Directory MEDIUM 5.0
CVE-2008-7008

HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup…

No fix yet
Fix from $1,600 2009-08-19
Plesk MEDIUM 5.8
CVE-2008-6984

Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a messag…

No fix yet
Fix from $1,600 2009-08-19
Coldfusion MEDIUM 5.8
CVE-2009-1878

Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors.

Fix: after 8.0.1
Fix from $1,600 2009-08-18
Websphere Application Server MEDIUM 6.5
CVE-2009-0906

The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated u…

Patch available
Fix from $1,600 2009-08-13
Websphere Application Server HIGH 7.5
CVE-2009-2085

The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity …

Patch available
Fix from $1,950 2009-08-13
Websphere Application Server HIGH 7.5
CVE-2009-2088

The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single S…

Patch available
Fix from $1,950 2009-08-13
Aj Auction HIGH 7.5
CVE-2008-6965

AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called di…

No fix yet
Fix from $1,950 2009-08-13
Web Hosting Directory HIGH 7.5
CVE-2008-6939

TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie …

No fix yet
Fix from $1,950 2009-08-12
Collabtive HIGH 7.5
CVE-2008-6947EPSS 8%

Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via unspecified vectors associated …

No fix yet
Fix from $1,950 2009-08-12
Maurycms HIGH 7.5
CVE-2008-6951

MauryCMS 0.53.2 and earlier does not require administrative authentication for Editors/fckeditor/editor/filemanager/browser/default/browser.html, whi…

No fix yet
Fix from $1,950 2009-08-12
Taskdriver HIGH 7.5
CVE-2008-6919

profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie…

Fix: after 1.3
Fix from $1,950 2009-08-10
Zodb HIGH 7.5
CVE-2009-0669

Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass a…

Fix: after 3.8.1
Fix from $1,950 2009-08-07
Speedstream 5200 HIGH 10.0
CVE-2008-6916

Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host header, possibly involving a …

No fix yet
Fix from $1,950 2009-08-07
Shaadiclone HIGH 7.5
CVE-2008-6912EPSS 7%

Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin/home.php.

No fix yet
Fix from $1,950 2009-08-07
Sssd HIGH 7.5
CVE-2009-2410

The local_handler_callback function in server/responder/pam/pam_LOCAL_domain.c in sssd 0.4.1 does not properly handle blank-password accounts in the …

No fix yet
Fix from $1,950 2009-07-30
Desi Short Url Script HIGH 7.5
CVE-2009-2642

index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to 1 and the uid cookie to an in…

No fix yet
Fix from $1,950 2009-07-28
Movable Type MEDIUM 5.8
CVE-2009-2481

mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restriction…

Fix: after 4.26
Fix from $1,600 2009-07-16
Absolute Faq Manager .net HIGH 7.5
CVE-2008-6854

Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a …

No fix yet
Fix from $1,950 2009-07-14
Absolute News Feed HIGH 7.5
CVE-2008-6855

Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a c…

No fix yet
Fix from $1,950 2009-07-14
Absolute News Manager.net HIGH 7.5
CVE-2008-6856

Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a…

No fix yet
Fix from $1,950 2009-07-14
Absolute Podcast.net HIGH 7.5
CVE-2008-6857

Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

No fix yet
Fix from $1,950 2009-07-14
Absolute Banner Manager.net HIGH 7.5
CVE-2008-6858

Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain val…

No fix yet
Fix from $1,950 2009-07-14
Absolute Control Panel Xe HIGH 7.5
CVE-2008-6859

Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a…

No fix yet
Fix from $1,950 2009-07-14
Absolute Poll Manager Xe HIGH 7.5
CVE-2008-6860

Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a …

No fix yet
Fix from $1,950 2009-07-14
Absolute Newsletter HIGH 7.5
CVE-2008-6861

Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to…

No fix yet
Fix from $1,950 2009-07-14
Absolute Content Rotator HIGH 7.5
CVE-2008-6862

Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

No fix yet
Fix from $1,950 2009-07-14
Absolute Form Processor.net HIGH 7.5
CVE-2008-6863

Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie t…

No fix yet
Fix from $1,950 2009-07-14
Absolute Live Support .net HIGH 7.5
CVE-2008-6864

Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to …

No fix yet
Fix from $1,950 2009-07-14