CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (1,670)
page 48 of 84| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2008-4081 | 0.03 | — | 0.02 | Sep 15, 2008 | admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie. | ||
| CVE-2008-3407 | 0.03 | — | 0.03 | Jul 31, 2008 | phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie. | ||
| CVE-2008-3320 | 0.03 | — | 0.04 | Jul 25, 2008 | admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary gbook_cookie cookie. | ||
| CVE-2008-3322 | 0.03 | — | 0.05 | Jul 25, 2008 | admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary recipe_cookie cookie. | ||
| CVE-2008-3299 | 0.03 | — | 0.01 | Jul 25, 2008 | eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng cookie value to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | ||
| CVE-2008-3292 | 0.03 | — | 0.02 | Jul 24, 2008 | constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin cookie, as demonstrated via addpage.php. | ||
| CVE-2008-3211 | 0.03 | — | 0.05 | Jul 18, 2008 | Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1. | ||
| CVE-2008-3203 | 0.03 | — | 0.05 | Jul 17, 2008 | js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter. | ||
| CVE-2008-3033 | 0.03 | — | 0.02 | Jul 7, 2008 | RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php. | ||
| CVE-2008-2920 | 0.03 | — | 0.06 | Jun 30, 2008 | admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files. | ||
| CVE-2008-2833 | 0.03 | — | 0.04 | Jun 24, 2008 | admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 parameter in conjunction with filenames in the filename and upload parameters. | ||
| CVE-2008-2347 | 0.03 | — | 0.03 | May 20, 2008 | MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting the userID parameter to "admin" in a direct request to admin/addUser.php. | ||
| CVE-2008-2298 | 0.03 | — | 0.03 | May 18, 2008 | Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1. | ||
| CVE-2008-2282 | 0.03 | — | 0.04 | May 18, 2008 | admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admin cookie to true. | ||
| CVE-2008-2269 | 0.03 | — | 0.03 | May 16, 2008 | AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by setting the gastracker_admin cookie to TRUE. | ||
| CVE-2008-1971 | 0.03 | — | 0.05 | Apr 27, 2008 | phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php. | ||
| CVE-2008-1904 | 0.03 | — | 0.05 | Apr 22, 2008 | Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attackers to obtain access to the "admin area" via a modified this_cookie cookie. | ||
| CVE-2008-1868 | 0.03 | — | 0.05 | Apr 17, 2008 | admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information. | ||
| CVE-2008-1727 | 0.03 | — | 0.04 | Apr 11, 2008 | KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts. | ||
| CVE-2008-1327 | 0.03 | — | 0.05 | Mar 13, 2008 | Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |
- CVE-2008-4081Sep 15, 2008risk 0.03cvss —epss 0.02
admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie.
- CVE-2008-3407Jul 31, 2008risk 0.03cvss —epss 0.03
phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie.
- CVE-2008-3320Jul 25, 2008risk 0.03cvss —epss 0.04
admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary gbook_cookie cookie.
- CVE-2008-3322Jul 25, 2008risk 0.03cvss —epss 0.05
admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary recipe_cookie cookie.
- CVE-2008-3299Jul 25, 2008risk 0.03cvss —epss 0.01
eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng cookie value to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
- CVE-2008-3292Jul 24, 2008risk 0.03cvss —epss 0.02
constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin cookie, as demonstrated via addpage.php.
- CVE-2008-3211Jul 18, 2008risk 0.03cvss —epss 0.05
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1.
- CVE-2008-3203Jul 17, 2008risk 0.03cvss —epss 0.05
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.
- CVE-2008-3033Jul 7, 2008risk 0.03cvss —epss 0.02
RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.
- CVE-2008-2920Jun 30, 2008risk 0.03cvss —epss 0.06
admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files.
- CVE-2008-2833Jun 24, 2008risk 0.03cvss —epss 0.04
admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 parameter in conjunction with filenames in the filename and upload parameters.
- CVE-2008-2347May 20, 2008risk 0.03cvss —epss 0.03
MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting the userID parameter to "admin" in a direct request to admin/addUser.php.
- CVE-2008-2298May 18, 2008risk 0.03cvss —epss 0.03
Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.
- CVE-2008-2282May 18, 2008risk 0.03cvss —epss 0.04
admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admin cookie to true.
- CVE-2008-2269May 16, 2008risk 0.03cvss —epss 0.03
AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by setting the gastracker_admin cookie to TRUE.
- CVE-2008-1971Apr 27, 2008risk 0.03cvss —epss 0.05
phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php.
- CVE-2008-1904Apr 22, 2008risk 0.03cvss —epss 0.05
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attackers to obtain access to the "admin area" via a modified this_cookie cookie.
- CVE-2008-1868Apr 17, 2008risk 0.03cvss —epss 0.05
admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information.
- CVE-2008-1727Apr 11, 2008risk 0.03cvss —epss 0.04
KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts.
- CVE-2008-1327Mar 13, 2008risk 0.03cvss —epss 0.05
Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.