CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (1,670)
page 47 of 84| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2008-5497 | 0.03 | — | 0.04 | Dec 12, 2008 | BandSite CMS 1.1.4 allows remote attackers to bypass authentication and gain administrative access by setting the login_auth cookie to true. | ||
| CVE-2008-5221 | 0.03 | — | 0.05 | Nov 25, 2008 | The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters. | ||
| CVE-2008-5219 | 0.03 | — | 0.04 | Nov 25, 2008 | The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters. | ||
| CVE-2008-5125 | 0.03 | — | 0.02 | Nov 18, 2008 | admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin. | ||
| CVE-2008-5065 | 0.03 | — | 0.02 | Nov 13, 2008 | TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBook_login cookie to admin. | ||
| CVE-2008-5042 | 0.03 | — | 0.05 | Nov 12, 2008 | Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admin/home.php. | ||
| CVE-2008-5040 | 0.03 | — | 0.02 | Nov 12, 2008 | Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1) myforum_login and (2) myforum_pass cookies to 1. | ||
| CVE-2008-4784 | 0.03 | — | 0.02 | Oct 29, 2008 | aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edit_delete.php, (2) edit_cat.php, (3) edit_lock.php, and (4) edit_form.php. | ||
| CVE-2008-4783 | 0.03 | — | 0.02 | Oct 29, 2008 | tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin." | ||
| CVE-2008-4752 | 0.03 | — | 0.02 | Oct 27, 2008 | TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login cookie to admin. | ||
| CVE-2008-4721 | 0.03 | — | 0.02 | Oct 23, 2008 | PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged." | ||
| CVE-2008-4714 | 0.03 | — | 0.02 | Oct 23, 2008 | Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies. | ||
| CVE-2008-4708 | 0.03 | — | 0.02 | Oct 23, 2008 | BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1. | ||
| CVE-2008-4649 | 0.03 | — | 0.01 | Oct 22, 2008 | Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | ||
| CVE-2008-4622 | 0.03 | — | 0.05 | Oct 21, 2008 | The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by setting the fn-loggedin cookie to 1. | ||
| CVE-2008-4427 | 0.03 | — | 0.06 | Oct 3, 2008 | changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows remote attackers to change arbitrary passwords. | ||
| CVE-2008-4319 | 0.03 | — | 0.03 | Sep 29, 2008 | fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string. | ||
| CVE-2008-4244 | 0.03 | — | 0.02 | Sep 25, 2008 | Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1. | ||
| CVE-2008-4146 | 0.03 | — | 0.04 | Sep 24, 2008 | Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field. | ||
| CVE-2008-4167 | 0.03 | — | 0.05 | Sep 22, 2008 | useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account. |
- CVE-2008-5497Dec 12, 2008risk 0.03cvss —epss 0.04
BandSite CMS 1.1.4 allows remote attackers to bypass authentication and gain administrative access by setting the login_auth cookie to true.
- CVE-2008-5221Nov 25, 2008risk 0.03cvss —epss 0.05
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters.
- CVE-2008-5219Nov 25, 2008risk 0.03cvss —epss 0.04
The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.
- CVE-2008-5125Nov 18, 2008risk 0.03cvss —epss 0.02
admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin.
- CVE-2008-5065Nov 13, 2008risk 0.03cvss —epss 0.02
TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBook_login cookie to admin.
- CVE-2008-5042Nov 12, 2008risk 0.03cvss —epss 0.05
Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admin/home.php.
- CVE-2008-5040Nov 12, 2008risk 0.03cvss —epss 0.02
Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1) myforum_login and (2) myforum_pass cookies to 1.
- CVE-2008-4784Oct 29, 2008risk 0.03cvss —epss 0.02
aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edit_delete.php, (2) edit_cat.php, (3) edit_lock.php, and (4) edit_form.php.
- CVE-2008-4783Oct 29, 2008risk 0.03cvss —epss 0.02
tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin."
- CVE-2008-4752Oct 27, 2008risk 0.03cvss —epss 0.02
TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login cookie to admin.
- CVE-2008-4721Oct 23, 2008risk 0.03cvss —epss 0.02
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged."
- CVE-2008-4714Oct 23, 2008risk 0.03cvss —epss 0.02
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.
- CVE-2008-4708Oct 23, 2008risk 0.03cvss —epss 0.02
BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1.
- CVE-2008-4649Oct 22, 2008risk 0.03cvss —epss 0.01
Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
- CVE-2008-4622Oct 21, 2008risk 0.03cvss —epss 0.05
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by setting the fn-loggedin cookie to 1.
- CVE-2008-4427Oct 3, 2008risk 0.03cvss —epss 0.06
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows remote attackers to change arbitrary passwords.
- CVE-2008-4319Sep 29, 2008risk 0.03cvss —epss 0.03
fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.
- CVE-2008-4244Sep 25, 2008risk 0.03cvss —epss 0.02
Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1.
- CVE-2008-4146Sep 24, 2008risk 0.03cvss —epss 0.04
Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field.
- CVE-2008-4167Sep 22, 2008risk 0.03cvss —epss 0.05
useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account.