Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2009-2003
Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7porta…
Password Protector Sd
No fix yet
HIGH 7.5
CVE-2009-1854
Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1.
Million Dollar Text Links
No fix yet
MEDIUM 6.5
CVE-2009-1826
modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote authenticated users to list user…
Mygesuad
No fix yet
MEDIUM 5.0
CVE-2009-1384
pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user accou…
Pam Krb5
Mitigation only
MEDIUM 5.0
CVE-2008-6815
mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a d…
Myktools
No fix yet
HIGH 10.0
CVE-2008-6816
Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a custom action to the MGE fron…
Network Shutdown Module
after 3.1_beta
HIGH 7.5
CVE-2009-1670EPSS 7%
user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vecto…
Tcpdb
No fix yet
HIGH 7.5
CVE-2009-1664
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attacke…
Answer And Question Script
No fix yet
HIGH 7.5
CVE-2009-1638
Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin …
Job Career Package
No fix yet
MEDIUM 5.8
CVE-2009-1580
Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie.
Squirrelmail
after 1.4.17
MEDIUM 6.8
CVE-2009-1629
ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it …
Ajaxterm
after 0.10
HIGH 7.5
CVE-2009-1617
Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin …
Linktracker
No fix yet
HIGH 7.5
CVE-2009-1618
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value…
Livehelp
No fix yet
HIGH 7.5
CVE-2009-1619
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1.
Filestream
No fix yet
HIGH 7.5
CVE-2008-6804
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOK…
Tribiq Cms
No fix yet
MEDIUM 6.5
CVE-2009-1596
Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which …
Openfire
3.6.5+
HIGH 7.5
CVE-2009-1587
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, l…
Php Site Lock
No fix yet
HIGH 7.5
CVE-2009-1549EPSS 9%
AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto."
Agtc Myshop
No fix yet
HIGH 7.5
CVE-2009-1504
Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "…
Absolute Control Panel Xe
No fix yet
HIGH 7.5
CVE-2009-1489
includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie paramete…
Fungamez
No fix yet
HIGH 7.5
CVE-2008-6763EPSS 7%
login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logge…
Silentum Loginsys
No fix yet
MEDIUM 6.0
CVE-2009-0662
The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authent…
Plonepas
Patch available
HIGH 7.5
CVE-2008-6743
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary val…
Rsmscript
No fix yet
HIGH 7.5
CVE-2008-6738
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1.
Myshoutpro
No fix yet
HIGH 7.5
CVE-2008-6739
Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain adminis…
Asp Download
No fix yet
HIGH 7.5
CVE-2008-6723
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cook…
Entertainment Portal
No fix yet
HIGH 7.5
CVE-2008-6716
homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to have an un…
Pre Ads Portal
after 2.0
HIGH 7.5
CVE-2008-6717
U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers…
Signup
No fix yet
HIGH 7.5
CVE-2008-6718
U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to …
Justbookit
No fix yet
HIGH 7.5
CVE-2008-6719
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows r…
Justlistit
No fix yet