Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2009-2003 Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7porta… Password Protector Sd No fix yet Fix from $1,9502009-06-08 HIGH 7.5 CVE-2009-1854 Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1. Million Dollar Text Links No fix yet Fix from $1,9502009-06-01 MEDIUM 6.5 CVE-2009-1826 modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote authenticated users to list user… Mygesuad No fix yet Fix from $1,6002009-05-29 MEDIUM 5.0 CVE-2009-1384 pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user accou… Pam Krb5 Mitigation only Fix from $1,6002009-05-28 MEDIUM 5.0 CVE-2008-6815 mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a d… Myktools No fix yet Fix from $1,6002009-05-28 HIGH 10.0 CVE-2008-6816 Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a custom action to the MGE fron… Network Shutdown Module after 3.1_beta Fix from $1,9502009-05-28 HIGH 7.5 CVE-2009-1670EPSS 7% user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vecto… Tcpdb No fix yet Fix from $1,9502009-05-18 HIGH 7.5 CVE-2009-1664 myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attacke… Answer And Question Script No fix yet Fix from $1,9502009-05-18 HIGH 7.5 CVE-2009-1638 Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin … Job Career Package No fix yet Fix from $1,9502009-05-15 MEDIUM 5.8 CVE-2009-1580 Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie. Squirrelmail after 1.4.17 Fix from $1,6002009-05-14 MEDIUM 6.8 CVE-2009-1629 ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it … Ajaxterm after 0.10 Fix from $1,6002009-05-14 HIGH 7.5 CVE-2009-1617 Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin … Linktracker No fix yet Fix from $1,9502009-05-12 HIGH 7.5 CVE-2009-1618 Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value… Livehelp No fix yet Fix from $1,9502009-05-12 HIGH 7.5 CVE-2009-1619 Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1. Filestream No fix yet Fix from $1,9502009-05-12 HIGH 7.5 CVE-2008-6804 Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOK… Tribiq Cms No fix yet Fix from $1,9502009-05-11 MEDIUM 6.5 CVE-2009-1596 Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which … Openfire 3.6.5+ Fix from $1,6002009-05-11 HIGH 7.5 CVE-2009-1587 index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, l… Php Site Lock No fix yet Fix from $1,9502009-05-07 HIGH 7.5 CVE-2009-1549EPSS 9% AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto." Agtc Myshop No fix yet Fix from $1,9502009-05-06 HIGH 7.5 CVE-2009-1504 Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "… Absolute Control Panel Xe No fix yet Fix from $1,9502009-05-01 HIGH 7.5 CVE-2009-1489 includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie paramete… Fungamez No fix yet Fix from $1,9502009-04-29 HIGH 7.5 CVE-2008-6763EPSS 7% login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logge… Silentum Loginsys No fix yet Fix from $1,9502009-04-28 MEDIUM 6.0 CVE-2009-0662 The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authent… Plonepas Patch available Fix from $1,6002009-04-23 HIGH 7.5 CVE-2008-6743 RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary val… Rsmscript No fix yet Fix from $1,9502009-04-22 HIGH 7.5 CVE-2008-6738 MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1. Myshoutpro No fix yet Fix from $1,9502009-04-21 HIGH 7.5 CVE-2008-6739 Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain adminis… Asp Download No fix yet Fix from $1,9502009-04-21 HIGH 7.5 CVE-2008-6723 TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cook… Entertainment Portal No fix yet Fix from $1,9502009-04-14 HIGH 7.5 CVE-2008-6716 homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to have an un… Pre Ads Portal after 2.0 Fix from $1,9502009-04-13 HIGH 7.5 CVE-2008-6717 U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers… Signup No fix yet Fix from $1,9502009-04-13 HIGH 7.5 CVE-2008-6718 U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to … Justbookit No fix yet Fix from $1,9502009-04-13 HIGH 7.5 CVE-2008-6719 U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows r… Justlistit No fix yet Fix from $1,9502009-04-13