Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Chameleon Cms HIGH 7.5
CVE-2007-3050

Session fixation vulnerability in chameleon cms 3.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

Fix: after 3.0
Fix from $1,950 2007-06-06
Systems Insight Manager HIGH 10.0
CVE-2007-2719

Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting …

Patch available
Fix from $1,950 2007-05-16
Simple Machines Forum MEDIUM 6.8
CVE-2007-2546

Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESS…

Fix: after 1.1.2
Fix from $1,600 2007-05-09
Plogger HIGH 7.5
CVE-2007-2277

Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

Mitigation only
Fix from $1,950 2007-04-25
Openssh MEDIUM 5.0
CVE-2007-2243

OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by atte…

Mitigation only
Fix from $1,600 2007-04-25
Content Management System CRITICAL 9.1
CVE-2007-1966

Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.

Patch available
Fix from $2,300 2007-04-11
Content Management System HIGH 7.5
CVE-2007-1949

Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.

Mitigation only
Fix from $1,950 2007-04-11
Oboshop HIGH 7.5
CVE-2007-1951

Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.

Mitigation only
Fix from $1,950 2007-04-11
Onebyone Cms HIGH 7.5
CVE-2007-1952

Session fixation vulnerability in onelook onebyone CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.

Mitigation only
Fix from $1,950 2007-04-11
Courts Online HIGH 7.5
CVE-2007-1953

Session fixation vulnerability in onelook courts on-line allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.

Mitigation only
Fix from $1,950 2007-04-11
Creative Guestbook HIGH 7.5
CVE-2007-1480

Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWOR…

No fix yet
Fix from $1,950 2007-03-16
Webspell HIGH 10.0
CVE-2007-1160

webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-…

Mitigation only
Fix from $1,950 2007-03-02
Unified Ip Conference Station 7935 Firmware HIGH 10.0
CVE-2007-1062

The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP se…

Fix: after 3.3
Fix from $1,950 2007-02-22
Mailenable Enterprise HIGH 10.0
CVE-2006-6997

Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edi…

No fix yet
Fix from $1,950 2007-02-12
Speedport 500v HIGH 7.5
CVE-2007-0435

T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the device via a LOGINKEY=TECOM cooki…

Mitigation only
Fix from $1,950 2007-01-23
Logahead Unu HIGH 7.5
CVE-2006-6783

logahead UNU 1.0 before 20061226 allows remote attackers to upload arbitrary files via unspecified vectors related to plugins/widged/_widged.php (aka…

Mitigation only
Fix from $1,950 2006-12-28
Koukyoumuke Soumu Workflow MEDIUM 5.0
CVE-2006-6705

Multiple unspecified vulnerabilities in the template files in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, an…

Mitigation only
Fix from $1,600 2006-12-23
Sql Ledger HIGH 7.5
CVE-2006-4244

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessioni…

No fix yet
Fix from $1,950 2006-08-31
3000cn MEDIUM 6.4
CVE-2006-2113

The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuj…

Patch available
Fix from $1,600 2006-08-25
Jetbox Cms HIGH 7.5
CVE-2006-3583

Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator section.

Mitigation only
Fix from $1,950 2006-08-08
Newscmslite HIGH 7.5
CVE-2006-2636

newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn coo…

No fix yet
Fix from $1,950 2006-05-30
Realvnc HIGH 7.5
CVE-2006-2369EPSS 92%

RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a…

Patch available
Fix from $1,950 2006-05-15
Quagga Routing Software Suite MEDIUM 5.0
CVE-2006-2224EPSS 10%

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify rou…

Fix: after 0.99.3
Fix from $1,600 2006-05-05
Drupal MEDIUM 5.1
CVE-2006-1228

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to c…

Patch available
Fix from $1,600 2006-03-14
Invision Power Board MEDIUM 6.4
CVE-2006-0633

The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create …

Patch available
Fix from $1,600 2006-02-10
Sleeperchat MEDIUM 5.0
CVE-2006-0416

SleeperChat 0.3f and earlier allows remote attackers to bypass authentication and create new entries via the txt parameter to (1) chat_no.php and (2)…

Fix: after 0.3f
Fix from $1,600 2006-01-25
P202s HIGH 7.5
CVE-2006-0374

Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might a…

Mitigation only
Fix from $1,950 2006-01-22
Ragnarok Online Control Panel HIGH 7.5
CVE-2005-4861

functions.php in Ragnarok Online Control Panel (ROCP) 4.3.4a allows remote attackers to bypass authentication by requesting account_manage.php with a…

Mitigation only
Fix from $1,950 2005-12-31
Sapid Cms HIGH 7.5
CVE-2005-4006

SAPID CMS before 1.2.3.03 allows remote attackers to bypass authentication via direct requests to the usr/system files (1) insert_file.php, (2) inser…

Fix: after 1.2.3.02
Fix from $1,950 2005-12-05
Coppermine Photo Gallery MEDIUM 5.0
CVE-2005-3979

relocate_server.php in Coppermine Photo Gallery (CPG) 1.4.2 and 1.4 beta is not removed after installation and does not use authentication, which all…

Mitigation only
Fix from $1,600 2005-12-03