CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (1,670)
page 46 of 84| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2008-6411 | 0.03 | — | 0.02 | Mar 6, 2009 | Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1. | ||
| CVE-2008-6307 | 0.03 | — | 0.03 | Feb 26, 2009 | E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin." | ||
| CVE-2008-6300 | 0.03 | — | 0.03 | Feb 26, 2009 | Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | ||
| CVE-2008-6269 | 0.03 | — | 0.02 | Feb 25, 2009 | Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username cookies for user privileges; (2) session_admin_id, session_admin_username, and session_admin cookies for admin privileges; and (3) session_staff_id, session_staff_username, and session_staff cookies for staff users. | ||
| CVE-2008-6162 | 0.03 | — | 0.02 | Feb 20, 2009 | Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNick cookie to admin. | ||
| CVE-2008-6143 | 0.03 | — | 0.01 | Feb 16, 2009 | OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie. | ||
| CVE-2009-0360 | 0.03 | — | 0.00 | Feb 13, 2009 | Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application. | ||
| CVE-2008-6118 | 0.03 | — | 0.03 | Feb 11, 2009 | win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1. | ||
| CVE-2009-0461 | 0.03 | — | 0.02 | Feb 10, 2009 | Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie. | ||
| CVE-2009-0460 | 0.03 | — | 0.02 | Feb 10, 2009 | Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie. | ||
| CVE-2008-6092 | 0.03 | — | 0.02 | Feb 9, 2009 | phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie. | ||
| CVE-2008-6045 | 0.03 | — | 0.02 | Feb 3, 2009 | Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter. | ||
| CVE-2008-6009 | 0.03 | — | 0.02 | Jan 30, 2009 | SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1. | ||
| CVE-2009-0280 | 0.03 | — | 0.03 | Jan 27, 2009 | Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1. | ||
| CVE-2008-5967 | 0.03 | — | 0.05 | Jan 26, 2009 | admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root. | ||
| CVE-2008-5945 | 0.03 | — | 0.02 | Jan 22, 2009 | Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | ||
| CVE-2008-5880 | 0.03 | — | 0.02 | Jan 8, 2009 | admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok". | ||
| CVE-2008-5708 | 0.03 | — | 0.05 | Dec 24, 2008 | redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1. | ||
| CVE-2008-5692 | 0.03 | — | 0.01 | Dec 19, 2008 | Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name. | ||
| CVE-2008-5576 | 0.03 | — | 0.02 | Dec 15, 2008 | admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter. |
- CVE-2008-6411Mar 6, 2009risk 0.03cvss —epss 0.02
Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1.
- CVE-2008-6307Feb 26, 2009risk 0.03cvss —epss 0.03
E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin."
- CVE-2008-6300Feb 26, 2009risk 0.03cvss —epss 0.03
Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
- CVE-2008-6269Feb 25, 2009risk 0.03cvss —epss 0.02
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username cookies for user privileges; (2) session_admin_id, session_admin_username, and session_admin cookies for admin privileges; and (3) session_staff_id, session_staff_username, and session_staff cookies for staff users.
- CVE-2008-6162Feb 20, 2009risk 0.03cvss —epss 0.02
Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNick cookie to admin.
- CVE-2008-6143Feb 16, 2009risk 0.03cvss —epss 0.01
OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie.
- CVE-2009-0360Feb 13, 2009risk 0.03cvss —epss 0.00
Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.
- CVE-2008-6118Feb 11, 2009risk 0.03cvss —epss 0.03
win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1.
- CVE-2009-0461Feb 10, 2009risk 0.03cvss —epss 0.02
Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.
- CVE-2009-0460Feb 10, 2009risk 0.03cvss —epss 0.02
Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.
- CVE-2008-6092Feb 9, 2009risk 0.03cvss —epss 0.02
phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie.
- CVE-2008-6045Feb 3, 2009risk 0.03cvss —epss 0.02
Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter.
- CVE-2008-6009Jan 30, 2009risk 0.03cvss —epss 0.02
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.
- CVE-2009-0280Jan 27, 2009risk 0.03cvss —epss 0.03
Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.
- CVE-2008-5967Jan 26, 2009risk 0.03cvss —epss 0.05
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.
- CVE-2008-5945Jan 22, 2009risk 0.03cvss —epss 0.02
Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
- CVE-2008-5880Jan 8, 2009risk 0.03cvss —epss 0.02
admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok".
- CVE-2008-5708Dec 24, 2008risk 0.03cvss —epss 0.05
redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.
- CVE-2008-5692Dec 19, 2008risk 0.03cvss —epss 0.01
Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.
- CVE-2008-5576Dec 15, 2008risk 0.03cvss —epss 0.02
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.