Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2007-3050 Session fixation vulnerability in chameleon cms 3.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. Chameleon Cms after 3.0 Fix from $1,9502007-06-06 HIGH 10.0 CVE-2007-2719 Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting … Systems Insight Manager Patch available Fix from $1,9502007-05-16 MEDIUM 6.8 CVE-2007-2546 Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESS… Simple Machines Forum after 1.1.2 Fix from $1,6002007-05-09 HIGH 7.5 CVE-2007-2277 Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. Plogger Mitigation only Fix from $1,9502007-04-25 MEDIUM 5.0 CVE-2007-2243 OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by atte… Openssh Mitigation only Fix from $1,6002007-04-25 CRITICAL 9.1 CVE-2007-1966 Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie. Content Management System Patch available Fix from $2,3002007-04-11 HIGH 7.5 CVE-2007-1949 Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. Content Management System Mitigation only Fix from $1,9502007-04-11 HIGH 7.5 CVE-2007-1951 Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. Oboshop Mitigation only Fix from $1,9502007-04-11 HIGH 7.5 CVE-2007-1952 Session fixation vulnerability in onelook onebyone CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. Onebyone Cms Mitigation only Fix from $1,9502007-04-11 HIGH 7.5 CVE-2007-1953 Session fixation vulnerability in onelook courts on-line allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. Courts Online Mitigation only Fix from $1,9502007-04-11 HIGH 7.5 CVE-2007-1480 Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWOR… Creative Guestbook No fix yet Fix from $1,9502007-03-16 HIGH 10.0 CVE-2007-1160 webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-… Webspell Mitigation only Fix from $1,9502007-03-02 HIGH 10.0 CVE-2007-1062 The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP se… Unified Ip Conference Station 7935 Firmware after 3.3 Fix from $1,9502007-02-22 HIGH 10.0 CVE-2006-6997 Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edi… Mailenable Enterprise No fix yet Fix from $1,9502007-02-12 HIGH 7.5 CVE-2007-0435 T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the device via a LOGINKEY=TECOM cooki… Speedport 500v Mitigation only Fix from $1,9502007-01-23 HIGH 7.5 CVE-2006-6783 logahead UNU 1.0 before 20061226 allows remote attackers to upload arbitrary files via unspecified vectors related to plugins/widged/_widged.php (aka… Logahead Unu Mitigation only Fix from $1,9502006-12-28 MEDIUM 5.0 CVE-2006-6705 Multiple unspecified vulnerabilities in the template files in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, an… Koukyoumuke Soumu Workflow Mitigation only Fix from $1,6002006-12-23 HIGH 7.5 CVE-2006-4244 SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessioni… Sql Ledger No fix yet Fix from $1,9502006-08-31 MEDIUM 6.4 CVE-2006-2113 The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuj… 3000cn Patch available Fix from $1,6002006-08-25 HIGH 7.5 CVE-2006-3583 Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator section. Jetbox Cms Mitigation only Fix from $1,9502006-08-08 HIGH 7.5 CVE-2006-2636 newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn coo… Newscmslite No fix yet Fix from $1,9502006-05-30 HIGH 7.5 CVE-2006-2369EPSS 92% RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a… Realvnc Patch available Fix from $1,9502006-05-15 MEDIUM 5.0 CVE-2006-2224EPSS 10% RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify rou… Quagga Routing Software Suite after 0.99.3 Fix from $1,6002006-05-05 MEDIUM 5.1 CVE-2006-1228 Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to c… Drupal Patch available Fix from $1,6002006-03-14 MEDIUM 6.4 CVE-2006-0633 The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create … Invision Power Board Patch available Fix from $1,6002006-02-10 MEDIUM 5.0 CVE-2006-0416 SleeperChat 0.3f and earlier allows remote attackers to bypass authentication and create new entries via the txt parameter to (1) chat_no.php and (2)… Sleeperchat after 0.3f Fix from $1,6002006-01-25 HIGH 7.5 CVE-2006-0374 Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might a… P202s Mitigation only Fix from $1,9502006-01-22 HIGH 7.5 CVE-2005-4861 functions.php in Ragnarok Online Control Panel (ROCP) 4.3.4a allows remote attackers to bypass authentication by requesting account_manage.php with a… Ragnarok Online Control Panel Mitigation only Fix from $1,9502005-12-31 HIGH 7.5 CVE-2005-4006 SAPID CMS before 1.2.3.03 allows remote attackers to bypass authentication via direct requests to the usr/system files (1) insert_file.php, (2) inser… Sapid Cms after 1.2.3.02 Fix from $1,9502005-12-05 MEDIUM 5.0 CVE-2005-3979 relocate_server.php in Coppermine Photo Gallery (CPG) 1.4.2 and 1.4 beta is not removed after installation and does not use authentication, which all… Coppermine Photo Gallery Mitigation only Fix from $1,6002005-12-03