CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (1,670)
page 44 of 84| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2009-2328 | 0.03 | — | 0.00 | Jul 5, 2009 | admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitrary accounts and conduct SQL injection attacks via the del_user_id parameter. | ||
| CVE-2009-2257 | 0.03 | — | 0.04 | Jun 30, 2009 | The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to (1) gateway/commands/saveconfig.html, and (2) stattbl.htm, (3) modemmenu.htm, (4) onload.htm, (5) form.css, (6) utility.js, and possibly (7) indextop.htm in html/. | ||
| CVE-2009-2233 | 0.03 | — | 0.01 | Jun 26, 2009 | The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the awse_logged cookie to 1. | ||
| CVE-2009-2231 | 0.03 | — | 0.01 | Jun 26, 2009 | MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record in a MIDAS cookie. | ||
| CVE-2009-2117 | 0.03 | — | 0.01 | Jun 18, 2009 | uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username. | ||
| CVE-2009-2040 | 0.03 | — | 0.03 | Jun 12, 2009 | admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative accounts via a manage_admin action in a direct request. | ||
| CVE-2009-2003 | 0.03 | — | 0.01 | Jun 8, 2009 | Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7portal and (2) cookname cookies to "admin." | ||
| CVE-2009-1854 | 0.03 | — | 0.01 | Jun 1, 2009 | Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1. | ||
| CVE-2009-1826 | 0.03 | — | 0.03 | May 29, 2009 | modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action. | ||
| CVE-2009-1825 | 0.03 | — | 0.04 | May 29, 2009 | modules/admuser.php in myColex 1.4.2 does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action. | ||
| CVE-2008-6815 | 0.03 | — | 0.04 | May 28, 2009 | mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a direct request, and then sending an unspecified request to the download page for the backup. | ||
| CVE-2009-1670 | 0.03 | — | 0.03 | May 18, 2009 | user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vectors. NOTE: some of these details are obtained from third party information. | ||
| CVE-2009-1664 | 0.03 | — | 0.03 | May 18, 2009 | myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via modified userid, txtpassword, and txtRpassword parameters. | ||
| CVE-2009-1638 | 0.03 | — | 0.02 | May 15, 2009 | Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin cookie to Login. | ||
| CVE-2009-1619 | 0.03 | — | 0.02 | May 12, 2009 | Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1. | ||
| CVE-2009-1618 | 0.03 | — | 0.02 | May 12, 2009 | Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie. | ||
| CVE-2009-1617 | 0.03 | — | 0.02 | May 12, 2009 | Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin cookie. | ||
| CVE-2008-6804 | 0.03 | — | 0.02 | May 11, 2009 | Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NOTE: a third party reports that the vendor disputes the existence of this issue | ||
| CVE-2009-1587 | 0.03 | — | 0.02 | May 7, 2009 | index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, login_name, user_id, and user_type cookies to certain values. | ||
| CVE-2009-1549 | 0.03 | — | 0.03 | May 6, 2009 | AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto." |
- CVE-2009-2328Jul 5, 2009risk 0.03cvss —epss 0.00
admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitrary accounts and conduct SQL injection attacks via the del_user_id parameter.
- CVE-2009-2257Jun 30, 2009risk 0.03cvss —epss 0.04
The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to (1) gateway/commands/saveconfig.html, and (2) stattbl.htm, (3) modemmenu.htm, (4) onload.htm, (5) form.css, (6) utility.js, and possibly (7) indextop.htm in html/.
- CVE-2009-2233Jun 26, 2009risk 0.03cvss —epss 0.01
The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the awse_logged cookie to 1.
- CVE-2009-2231Jun 26, 2009risk 0.03cvss —epss 0.01
MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record in a MIDAS cookie.
- CVE-2009-2117Jun 18, 2009risk 0.03cvss —epss 0.01
uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username.
- CVE-2009-2040Jun 12, 2009risk 0.03cvss —epss 0.03
admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative accounts via a manage_admin action in a direct request.
- CVE-2009-2003Jun 8, 2009risk 0.03cvss —epss 0.01
Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7portal and (2) cookname cookies to "admin."
- CVE-2009-1854Jun 1, 2009risk 0.03cvss —epss 0.01
Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1.
- CVE-2009-1826May 29, 2009risk 0.03cvss —epss 0.03
modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action.
- CVE-2009-1825May 29, 2009risk 0.03cvss —epss 0.04
modules/admuser.php in myColex 1.4.2 does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action.
- CVE-2008-6815May 28, 2009risk 0.03cvss —epss 0.04
mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a direct request, and then sending an unspecified request to the download page for the backup.
- CVE-2009-1670May 18, 2009risk 0.03cvss —epss 0.03
user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vectors. NOTE: some of these details are obtained from third party information.
- CVE-2009-1664May 18, 2009risk 0.03cvss —epss 0.03
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via modified userid, txtpassword, and txtRpassword parameters.
- CVE-2009-1638May 15, 2009risk 0.03cvss —epss 0.02
Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin cookie to Login.
- CVE-2009-1619May 12, 2009risk 0.03cvss —epss 0.02
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1.
- CVE-2009-1618May 12, 2009risk 0.03cvss —epss 0.02
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie.
- CVE-2009-1617May 12, 2009risk 0.03cvss —epss 0.02
Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin cookie.
- CVE-2008-6804May 11, 2009risk 0.03cvss —epss 0.02
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NOTE: a third party reports that the vendor disputes the existence of this issue
- CVE-2009-1587May 7, 2009risk 0.03cvss —epss 0.02
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, login_name, user_id, and user_type cookies to certain values.
- CVE-2009-1549May 6, 2009risk 0.03cvss —epss 0.03
AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto."