VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (1,670)

page 46 of 84
  • CVE-2008-6411Mar 6, 2009
    risk 0.03cvss epss 0.02

    Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1.

  • CVE-2008-6307Feb 26, 2009
    risk 0.03cvss epss 0.03

    E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin."

  • CVE-2008-6300Feb 26, 2009
    risk 0.03cvss epss 0.03

    Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2008-6269Feb 25, 2009
    risk 0.03cvss epss 0.02

    Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username cookies for user privileges; (2) session_admin_id, session_admin_username, and session_admin cookies for admin privileges; and (3) session_staff_id, session_staff_username, and session_staff cookies for staff users.

  • CVE-2008-6162Feb 20, 2009
    risk 0.03cvss epss 0.02

    Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNick cookie to admin.

  • CVE-2008-6143Feb 16, 2009
    risk 0.03cvss epss 0.01

    OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie.

  • CVE-2009-0360Feb 13, 2009
    risk 0.03cvss epss 0.00

    Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.

  • CVE-2008-6118Feb 11, 2009
    risk 0.03cvss epss 0.03

    win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1.

  • CVE-2009-0461Feb 10, 2009
    risk 0.03cvss epss 0.02

    Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.

  • CVE-2009-0460Feb 10, 2009
    risk 0.03cvss epss 0.02

    Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.

  • CVE-2008-6092Feb 9, 2009
    risk 0.03cvss epss 0.02

    phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie.

  • CVE-2008-6045Feb 3, 2009
    risk 0.03cvss epss 0.02

    Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter.

  • CVE-2008-6009Jan 30, 2009
    risk 0.03cvss epss 0.02

    SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.

  • CVE-2009-0280Jan 27, 2009
    risk 0.03cvss epss 0.03

    Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.

  • CVE-2008-5967Jan 26, 2009
    risk 0.03cvss epss 0.05

    admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

  • CVE-2008-5945Jan 22, 2009
    risk 0.03cvss epss 0.02

    Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2008-5880Jan 8, 2009
    risk 0.03cvss epss 0.02

    admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok".

  • CVE-2008-5708Dec 24, 2008
    risk 0.03cvss epss 0.05

    redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.

  • CVE-2008-5692Dec 19, 2008
    risk 0.03cvss epss 0.01

    Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.

  • CVE-2008-5576Dec 15, 2008
    risk 0.03cvss epss 0.02

    admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.