Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2007-3050
Session fixation vulnerability in chameleon cms 3.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
Chameleon Cms
after 3.0
HIGH 10.0
CVE-2007-2719
Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting …
Systems Insight Manager
Patch available
MEDIUM 6.8
CVE-2007-2546
Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESS…
Simple Machines Forum
after 1.1.2
HIGH 7.5
CVE-2007-2277
Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
Plogger
Mitigation only
MEDIUM 5.0
CVE-2007-2243
OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by atte…
Openssh
Mitigation only
CRITICAL 9.1
CVE-2007-1966
Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.
Content Management System
Patch available
HIGH 7.5
CVE-2007-1949
Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
Content Management System
Mitigation only
HIGH 7.5
CVE-2007-1951
Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
Oboshop
Mitigation only
HIGH 7.5
CVE-2007-1952
Session fixation vulnerability in onelook onebyone CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
Onebyone Cms
Mitigation only
HIGH 7.5
CVE-2007-1953
Session fixation vulnerability in onelook courts on-line allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
Courts Online
Mitigation only
HIGH 7.5
CVE-2007-1480
Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWOR…
Creative Guestbook
No fix yet
HIGH 10.0
CVE-2007-1160
webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-…
Webspell
Mitigation only
HIGH 10.0
CVE-2007-1062
The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP se…
Unified Ip Conference Station 7935 Firmware
after 3.3
HIGH 10.0
CVE-2006-6997
Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edi…
Mailenable Enterprise
No fix yet
HIGH 7.5
CVE-2007-0435
T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the device via a LOGINKEY=TECOM cooki…
Speedport 500v
Mitigation only
HIGH 7.5
CVE-2006-6783
logahead UNU 1.0 before 20061226 allows remote attackers to upload arbitrary files via unspecified vectors related to plugins/widged/_widged.php (aka…
Logahead Unu
Mitigation only
MEDIUM 5.0
CVE-2006-6705
Multiple unspecified vulnerabilities in the template files in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, an…
Koukyoumuke Soumu Workflow
Mitigation only
HIGH 7.5
CVE-2006-4244
SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessioni…
Sql Ledger
No fix yet
MEDIUM 6.4
CVE-2006-2113
The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuj…
3000cn
Patch available
HIGH 7.5
CVE-2006-3583
Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator section.
Jetbox Cms
Mitigation only
HIGH 7.5
CVE-2006-2636
newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn coo…
Newscmslite
No fix yet
HIGH 7.5
CVE-2006-2369EPSS 92%
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a…
Realvnc
Patch available
MEDIUM 5.0
CVE-2006-2224EPSS 10%
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify rou…
Quagga Routing Software Suite
after 0.99.3
MEDIUM 5.1
CVE-2006-1228
Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to c…
Drupal
Patch available
MEDIUM 6.4
CVE-2006-0633
The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create …
Invision Power Board
Patch available
MEDIUM 5.0
CVE-2006-0416
SleeperChat 0.3f and earlier allows remote attackers to bypass authentication and create new entries via the txt parameter to (1) chat_no.php and (2)…
Sleeperchat
after 0.3f
HIGH 7.5
CVE-2006-0374
Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might a…
P202s
Mitigation only
HIGH 7.5
CVE-2005-4861
functions.php in Ragnarok Online Control Panel (ROCP) 4.3.4a allows remote attackers to bypass authentication by requesting account_manage.php with a…
Ragnarok Online Control Panel
Mitigation only
HIGH 7.5
CVE-2005-4006
SAPID CMS before 1.2.3.03 allows remote attackers to bypass authentication via direct requests to the usr/system files (1) insert_file.php, (2) inser…
Sapid Cms
after 1.2.3.02
MEDIUM 5.0
CVE-2005-3979
relocate_server.php in Coppermine Photo Gallery (CPG) 1.4.2 and 1.4 beta is not removed after installation and does not use authentication, which all…
Coppermine Photo Gallery
Mitigation only