Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2012-01-28 CVE-2012-0931 Improper Authentication vulnerability in Schneider-Electric Modicon Quantum PLC
Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.
network
low complexity
schneider-electric CWE-287
critical
9.8
2009-09-25 CVE-2009-3421 Improper Authentication vulnerability in Zenas Pao-Bacheca Guestbook 2.1
login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.
network
low complexity
zenas CWE-287
critical
9.8
2009-07-10 CVE-2009-2422 Improper Authentication vulnerability in multiple products
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.
network
low complexity
rubyonrails apple CWE-287
critical
9.8
2009-07-08 CVE-2009-2382 Improper Authentication vulnerability in Jay-Jayx0R PHPmyblockchecker 1.0.0055
admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin cookie to LOGGEDIN.
network
low complexity
jay-jayx0r CWE-287
critical
9.8
2009-06-22 CVE-2009-2168 Improper Authentication vulnerability in Egyplus 7Ammel 1.0.1
cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are incorrect, which allows remote attackers to bypass authentication by providing arbitrary username and password parameters.
network
low complexity
egyplus CWE-287
critical
9.8
2009-05-11 CVE-2009-1596 Improper Authentication vulnerability in Igniterealtime Openfire
Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.
network
low complexity
igniterealtime CWE-287
6.5