Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Sip Enablement Services MEDIUM 6.4
CVE-2008-6707

The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform aut…

Mitigation only
Fix from $1,600 2009-04-10
Xecms HIGH 7.5
CVE-2008-6714EPSS 12%

admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by setting the xecms_username co…

No fix yet
Fix from $1,950 2009-04-10
Adaptive Security Appliance 5500 HIGH 7.8
CVE-2009-1155

Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2(4)27, 8.0 before 8.0(4)25, a…

Patch available
Fix from $1,950 2009-04-09
Sh News HIGH 7.5
CVE-2008-6664

action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies…

No fix yet
Fix from $1,950 2009-04-08
A\+ Php Scripts News Management System HIGH 7.5
CVE-2008-6667

A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuse…

No fix yet
Fix from $1,950 2009-04-08
Phpaddedit HIGH 7.5
CVE-2008-6581

login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.

Patch available
Fix from $1,950 2009-04-02
Garoon MEDIUM 6.8
CVE-2008-6569

Session fixation vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack web sessions via the session ID in the login pa…

Mitigation only
Fix from $1,600 2009-03-31
Websphere Application Server MEDIUM 5.5
CVE-2009-0892

The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessi…

Patch available
Fix from $1,600 2009-03-31
Micro Cms HIGH 7.5
CVE-2008-6553

microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an administrator, which allows …

Fix: after 0.3.5
Fix from $1,950 2009-03-30
Openinvoice HIGH 7.5
CVE-2008-6523

auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOT…

No fix yet
Fix from $1,950 2009-03-25
Websphere Application Server MEDIUM 5.5
CVE-2009-0891

The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 …

Patch available
Fix from $1,600 2009-03-25
Bloginator HIGH 7.5
CVE-2009-1050

Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYourself cookie.

No fix yet
Fix from $1,950 2009-03-24
Phpshop MEDIUM 6.8
CVE-2008-6455

Session fixation vulnerability in Edikon phpShop 0.8.1 allows remote attackers to hijack web sessions via unspecified vectors. NOTE: the provenance …

No fix yet
Fix from $1,600 2009-03-13
S Cms HIGH 7.5
CVE-2009-0864

S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie.

No fix yet
Fix from $1,950 2009-03-10
Celerbb MEDIUM 6.8
CVE-2009-0853

login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via …

No fix yet
Fix from $1,600 2009-03-09
Yourplace HIGH 7.5
CVE-2008-6445

Unspecified vulnerability in YourPlace before 1.0.1 has unknown impact and attack vectors, possibly related to improper authentication and the abilit…

Fix: after 1.0
Fix from $1,950 2009-03-09
Cerberus Helpdesk MEDIUM 5.0
CVE-2008-6440

Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't…

Fix: after 3.3
Fix from $1,600 2009-03-06
Explay Cms HIGH 7.5
CVE-2008-6411

Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1.

Fix: after 2.1
Fix from $1,950 2009-03-06
Link Back Checker HIGH 7.5
CVE-2008-6307

E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin."

No fix yet
Fix from $1,950 2009-02-26
Unified Meetingplace Web Conferencing HIGH 9.0
CVE-2009-0614

Unspecified vulnerability in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) …

Fix: 6.0 / 7.0+
Fix from $1,950 2009-02-26
Galatolo Webmanager HIGH 7.5
CVE-2008-6300

Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass…

No fix yet
Fix from $1,950 2009-02-26
Joovili HIGH 7.5
CVE-2008-6269

Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) se…

No fix yet
Fix from $1,950 2009-02-25
Websphere Partner Gateway MEDIUM 6.5
CVE-2009-0440

IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authe…

Patch available
Fix from $1,600 2009-02-22
Veriface MEDIUM 6.9
CVE-2009-0655

Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.

No fix yet
Fix from $1,600 2009-02-20
Ruby MEDIUM 6.8
CVE-2009-0642

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote at…

No fix yet
Fix from $1,600 2009-02-20
Bux.to Clone Script HIGH 7.5
CVE-2008-6162

Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNic…

No fix yet
Fix from $1,950 2009-02-20
Owenpoll HIGH 7.5
CVE-2008-6143EPSS 6%

OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie.

No fix yet
Fix from $1,950 2009-02-16
Mozilocms MEDIUM 6.8
CVE-2008-6128

Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

Fix: after 1.10.2
Fix from $1,600 2009-02-13
Mozilowiki MEDIUM 6.0
CVE-2008-6131

Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

Fix: after 1.0.1
Fix from $1,600 2009-02-13
Pam Krb5 MEDIUM 6.2
CVE-2009-0360

Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows…

Fix: after 3.12
Fix from $1,600 2009-02-13