Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2009-04-29 CVE-2009-1489 Improper Authentication vulnerability in Rens Rikkerink Fungamez
includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie parameter.
network
low complexity
rens-rikkerink CWE-287
7.5
2009-04-28 CVE-2008-6763 Improper Authentication vulnerability in Hypersilence Silentum Loginsys 1.0.0
login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's username.
network
low complexity
hypersilence CWE-287
7.5
2009-04-23 CVE-2009-0662 Improper Authentication vulnerability in Plone Plonepas
The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.
network
plone CWE-287
6.0
2009-04-22 CVE-2008-6743 Improper Authentication vulnerability in Shock-Therapy Rsmscript 1.21
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.
network
low complexity
shock-therapy CWE-287
7.5
2009-04-21 CVE-2008-6739 Improper Authentication vulnerability in Toddwoolums ASP Download 1.03
Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct request.
network
low complexity
toddwoolums CWE-287
7.5
2009-04-21 CVE-2008-6738 Improper Authentication vulnerability in Mark Girling Myshoutpro 1.2
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1.
network
low complexity
mark-girling CWE-287
7.5
2009-04-14 CVE-2008-6723 Improper Authentication vulnerability in Turnkeyforms Entertainment Portal 2.0
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cookie to Administrator.
network
low complexity
turnkeyforms CWE-287
7.5
2009-04-13 CVE-2008-6719 Improper Authentication vulnerability in Uochm Justlistit 1.0
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) start.php, (2) aktivitet.php, (3) prop_aktivitet.php, (4) kategorier.php, (5) konfig.php, (6) security.php, (7) manual.php, and possibly (8) index.php.
network
low complexity
uochm CWE-287
7.5
2009-04-13 CVE-2008-6718 Improper Authentication vulnerability in Uochm Justbookit 1.0
U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) user_manual.php, (2) user_config.php, (3) user_kundnamn.php, (4) user_kundlista.php, (5) user_aktiva_kunder.php, (6) database.php, and possibly (7) index.php.
network
low complexity
uochm CWE-287
7.5
2009-04-13 CVE-2008-6717 Improper Authentication vulnerability in Uochm Signup 1.0/1.1
U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) adminstart.php, (2) admineventtype.php, (3) admineventdetails.php, (4) admineventlist.php, (5) adminuserslist.php, (6) adminleaderslist.php, (7) admindatabase.php, and possibly (8) index.php.
network
low complexity
uochm CWE-287
7.5