Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Password Protector Sd HIGH 7.5
CVE-2009-2003

Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7porta…

No fix yet
Fix from $1,950 2009-06-08
Million Dollar Text Links HIGH 7.5
CVE-2009-1854

Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1.

No fix yet
Fix from $1,950 2009-06-01
Mygesuad MEDIUM 6.5
CVE-2009-1826

modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote authenticated users to list user…

No fix yet
Fix from $1,600 2009-05-29
Pam Krb5 MEDIUM 5.0
CVE-2009-1384

pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user accou…

Mitigation only
Fix from $1,600 2009-05-28
Myktools MEDIUM 5.0
CVE-2008-6815

mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a d…

No fix yet
Fix from $1,600 2009-05-28
Network Shutdown Module HIGH 10.0
CVE-2008-6816

Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a custom action to the MGE fron…

Fix: after 3.1_beta
Fix from $1,950 2009-05-28
Tcpdb HIGH 7.5
CVE-2009-1670EPSS 7%

user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vecto…

No fix yet
Fix from $1,950 2009-05-18
Answer And Question Script HIGH 7.5
CVE-2009-1664

myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attacke…

No fix yet
Fix from $1,950 2009-05-18
Job Career Package HIGH 7.5
CVE-2009-1638

Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin …

No fix yet
Fix from $1,950 2009-05-15
Squirrelmail MEDIUM 5.8
CVE-2009-1580

Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie.

Fix: after 1.4.17
Fix from $1,600 2009-05-14
Ajaxterm MEDIUM 6.8
CVE-2009-1629

ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it …

Fix: after 0.10
Fix from $1,600 2009-05-14
Linktracker HIGH 7.5
CVE-2009-1617

Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin …

No fix yet
Fix from $1,950 2009-05-12
Livehelp HIGH 7.5
CVE-2009-1618

Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value…

No fix yet
Fix from $1,950 2009-05-12
Filestream HIGH 7.5
CVE-2009-1619

Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1.

No fix yet
Fix from $1,950 2009-05-12
Tribiq Cms HIGH 7.5
CVE-2008-6804

Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOK…

No fix yet
Fix from $1,950 2009-05-11
Openfire MEDIUM 6.5
CVE-2009-1596

Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which …

Fix: 3.6.5+
Fix from $1,600 2009-05-11
Php Site Lock HIGH 7.5
CVE-2009-1587

index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, l…

No fix yet
Fix from $1,950 2009-05-07
Agtc Myshop HIGH 7.5
CVE-2009-1549EPSS 9%

AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto."

No fix yet
Fix from $1,950 2009-05-06
Absolute Control Panel Xe HIGH 7.5
CVE-2009-1504

Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "…

No fix yet
Fix from $1,950 2009-05-01
Fungamez HIGH 7.5
CVE-2009-1489

includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie paramete…

No fix yet
Fix from $1,950 2009-04-29
Silentum Loginsys HIGH 7.5
CVE-2008-6763EPSS 7%

login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logge…

No fix yet
Fix from $1,950 2009-04-28
Plonepas MEDIUM 6.0
CVE-2009-0662

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authent…

Patch available
Fix from $1,600 2009-04-23
Rsmscript HIGH 7.5
CVE-2008-6743

RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary val…

No fix yet
Fix from $1,950 2009-04-22
Myshoutpro HIGH 7.5
CVE-2008-6738

MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1.

No fix yet
Fix from $1,950 2009-04-21
Asp Download HIGH 7.5
CVE-2008-6739

Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain adminis…

No fix yet
Fix from $1,950 2009-04-21
Entertainment Portal HIGH 7.5
CVE-2008-6723

TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cook…

No fix yet
Fix from $1,950 2009-04-14
Pre Ads Portal HIGH 7.5
CVE-2008-6716

homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to have an un…

Fix: after 2.0
Fix from $1,950 2009-04-13
Signup HIGH 7.5
CVE-2008-6717

U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers…

No fix yet
Fix from $1,950 2009-04-13
Justbookit HIGH 7.5
CVE-2008-6718

U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to …

No fix yet
Fix from $1,950 2009-04-13
Justlistit HIGH 7.5
CVE-2008-6719

U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows r…

No fix yet
Fix from $1,950 2009-04-13