Vulnerabilities (CVE)

Filtered by CWE-287
Total 3235 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-3923 1 Sun 2 Virtual Desktop Infrastructure, Virtualbox 2023-12-10 7.5 HIGH N/A
The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.
CVE-2009-0360 1 Eyrie 1 Pam-krb5 2023-12-10 6.2 MEDIUM N/A
Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.
CVE-2009-0460 1 Wholehogsoftware 1 Ware Support 2023-12-10 7.5 HIGH N/A
Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.
CVE-2008-5721 1 Sapporoworks 1 Blackjumbodog 2023-12-10 5.0 MEDIUM N/A
SapporoWorks BlackJumboDog (BJD) before 4.2.3 allows remote attackers to bypass authentication and obtain sensitive information via unspecified vectors.
CVE-2008-0926 1 Novell 1 Edirectory 2023-12-10 7.5 HIGH N/A
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.
CVE-2008-4319 1 Libra File Manager 1 Php Filemanager 2023-12-10 6.4 MEDIUM N/A
fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.
CVE-2008-6951 1 Cms.maury91 1 Maurycms 2023-12-10 7.5 HIGH N/A
MauryCMS 0.53.2 and earlier does not require administrative authentication for Editors/fckeditor/editor/filemanager/browser/default/browser.html, which allows remote attackers to upload arbitrary files via a direct request.
CVE-2009-0492 1 Simpleircbot 1 Simpleircbot 2023-12-10 10.0 HIGH N/A
Unspecified vulnerability in SimpleIrcBot before 1.0 Stable has unknown impact and attack vectors related to an "auth vulnerability."
CVE-2008-5809 1 Futomi 1 Access Analyzer Cgi 2023-12-10 5.8 MEDIUM N/A
futomi CGI Cafe Access Analyzer CGI Standard 4.0.1 and earlier and Access Analyzer CGI Professional 4.11.3 and earlier use a predictable session id, which makes it easier for remote attackers to hijack sessions, and obtain sensitive information about analysis results, via a modified id.
CVE-2009-0891 1 Ibm 1 Websphere Application Server 2023-12-10 5.5 MEDIUM N/A
The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33) does not properly enforce (1) nonce and (2) timestamp expiration values in WS-Security bindings as stored in the com.ibm.wsspi.wssecurity.core custom property, which allows remote authenticated users to conduct session hijacking attacks.
CVE-2009-3481 2 Isygen, Joomla 2 Com Icrmbasic, Joomla 2023-12-10 7.5 HIGH N/A
A certain interface in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-2406 1 Sun 1 Java Asp Server 2023-12-10 7.5 HIGH N/A
The administration application server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to bypass authentication via direct requests on TCP port 5102.
CVE-2008-6009 1 Sg Real Estate Portal 1 Sg Real Estate Portal 2023-12-10 7.5 HIGH N/A
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.
CVE-2009-3261 1 Livestreet 1 Livestreet 2023-12-10 7.5 HIGH N/A
update/update_0.1.2_to_0.2.php in LiveStreet 0.2 does not require administrative authentication, which allows remote attackers to perform DROP TABLE operations via unspecified vectors.
CVE-2008-5042 1 Zeeways 1 Photovideotube 2023-12-10 7.5 HIGH N/A
Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admin/home.php.
CVE-2009-2642 1 Desiscripts 1 Desi Short Url Script 2023-12-10 7.5 HIGH N/A
index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to 1 and the uid cookie to an integer value, as demonstrated by a value of 13.
CVE-2008-6855 1 Xigla 1 Absolute News Feed 2023-12-10 7.5 HIGH N/A
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.
CVE-2008-4649 1 Elxis 1 Elxis Cms 2023-12-10 7.5 HIGH N/A
Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
CVE-2009-2064 1 Microsoft 2 Internet Explorer, Pocket Ie 2023-12-10 6.8 MEDIUM N/A
Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."
CVE-2008-1321 1 Asg-sentry 1 Asg-sentry 2023-12-10 5.0 MEDIUM N/A
The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of service (service termination) via the exit command to TCP port 6162, or have other impacts via other commands.