Vulnerabilities > Improper Authentication
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-04-29 | CVE-2009-1489 | Improper Authentication vulnerability in Rens Rikkerink Fungamez includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie parameter. | 7.5 |
2009-04-28 | CVE-2008-6763 | Improper Authentication vulnerability in Hypersilence Silentum Loginsys 1.0.0 login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's username. | 7.5 |
2009-04-23 | CVE-2009-0662 | Improper Authentication vulnerability in Plone Plonepas The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors. | 6.0 |
2009-04-22 | CVE-2008-6743 | Improper Authentication vulnerability in Shock-Therapy Rsmscript 1.21 RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php. | 7.5 |
2009-04-21 | CVE-2008-6739 | Improper Authentication vulnerability in Toddwoolums ASP Download 1.03 Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct request. | 7.5 |
2009-04-21 | CVE-2008-6738 | Improper Authentication vulnerability in Mark Girling Myshoutpro 1.2 MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1. | 7.5 |
2009-04-14 | CVE-2008-6723 | Improper Authentication vulnerability in Turnkeyforms Entertainment Portal 2.0 TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cookie to Administrator. | 7.5 |
2009-04-13 | CVE-2008-6719 | Improper Authentication vulnerability in Uochm Justlistit 1.0 U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) start.php, (2) aktivitet.php, (3) prop_aktivitet.php, (4) kategorier.php, (5) konfig.php, (6) security.php, (7) manual.php, and possibly (8) index.php. | 7.5 |
2009-04-13 | CVE-2008-6718 | Improper Authentication vulnerability in Uochm Justbookit 1.0 U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) user_manual.php, (2) user_config.php, (3) user_kundnamn.php, (4) user_kundlista.php, (5) user_aktiva_kunder.php, (6) database.php, and possibly (7) index.php. | 7.5 |
2009-04-13 | CVE-2008-6717 | Improper Authentication vulnerability in Uochm Signup 1.0/1.1 U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) adminstart.php, (2) admineventtype.php, (3) admineventdetails.php, (4) admineventlist.php, (5) adminuserslist.php, (6) adminleaderslist.php, (7) admindatabase.php, and possibly (8) index.php. | 7.5 |