VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (1,670)

page 47 of 84
  • CVE-2008-5497Dec 12, 2008
    risk 0.03cvss epss 0.04

    BandSite CMS 1.1.4 allows remote attackers to bypass authentication and gain administrative access by setting the login_auth cookie to true.

  • CVE-2008-5221Nov 25, 2008
    risk 0.03cvss epss 0.05

    The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters.

  • CVE-2008-5219Nov 25, 2008
    risk 0.03cvss epss 0.04

    The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.

  • CVE-2008-5125Nov 18, 2008
    risk 0.03cvss epss 0.02

    admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin.

  • CVE-2008-5065Nov 13, 2008
    risk 0.03cvss epss 0.02

    TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBook_login cookie to admin.

  • CVE-2008-5042Nov 12, 2008
    risk 0.03cvss epss 0.05

    Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admin/home.php.

  • CVE-2008-5040Nov 12, 2008
    risk 0.03cvss epss 0.02

    Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1) myforum_login and (2) myforum_pass cookies to 1.

  • CVE-2008-4784Oct 29, 2008
    risk 0.03cvss epss 0.02

    aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edit_delete.php, (2) edit_cat.php, (3) edit_lock.php, and (4) edit_form.php.

  • CVE-2008-4783Oct 29, 2008
    risk 0.03cvss epss 0.02

    tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin."

  • CVE-2008-4752Oct 27, 2008
    risk 0.03cvss epss 0.02

    TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login cookie to admin.

  • CVE-2008-4721Oct 23, 2008
    risk 0.03cvss epss 0.02

    PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged."

  • CVE-2008-4714Oct 23, 2008
    risk 0.03cvss epss 0.02

    Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.

  • CVE-2008-4708Oct 23, 2008
    risk 0.03cvss epss 0.02

    BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1.

  • CVE-2008-4649Oct 22, 2008
    risk 0.03cvss epss 0.01

    Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

  • CVE-2008-4622Oct 21, 2008
    risk 0.03cvss epss 0.05

    The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by setting the fn-loggedin cookie to 1.

  • CVE-2008-4427Oct 3, 2008
    risk 0.03cvss epss 0.06

    changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows remote attackers to change arbitrary passwords.

  • CVE-2008-4319Sep 29, 2008
    risk 0.03cvss epss 0.03

    fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.

  • CVE-2008-4244Sep 25, 2008
    risk 0.03cvss epss 0.02

    Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1.

  • CVE-2008-4146Sep 24, 2008
    risk 0.03cvss epss 0.04

    Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field.

  • CVE-2008-4167Sep 22, 2008
    risk 0.03cvss epss 0.05

    useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account.