CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,376 vulnerabilities with CWE-287
CVE-2010-1910
Consona Live Assistance, Dynamic Agent, and Subscriber Assistance - Improper Authentication via Blank Hint Fields
CVE-2010-1613
Moodle 1.8.x-1.9.7 - Session Fixation via Default Session ID Regeneration Setting
CVE-2010-1596
Support Incident Tracker < 3.51 - Unauthenticated Authentication Bypass via Empty LDAP Password
CVE-2010-0744
aMSN 0.98.3 - SSL Man-in-the-Middle
CVE-2010-1222
CA XOsoft r12.5 - Improper Authentication via SOAP Request
CVE-2010-1221
CA XOsoft r12.0 and r12.5 - Improper Authentication via SOAP Request
CVE-2010-1191
Sahana disaster management system <0.6.2.2 - Auth Bypass
CVE-2010-0521
Mac OS X Server < 10.6.3 - Unauthenticated LDAP Information Disclosure via Directory Binding
CVE-2010-0498
Mac OS X < 10.6.3 - Privilege Escalation via Directory Services Record Name Processing
CVE-2010-1097
DeDeCMS 5.5 GBK - Authentication Bypass via _SESSION[dede_admin_id] Parameter
CVE-2010-1040
OpenPNE 1.6-1.8 2.0-2.8 2.10-2.14 3.0-3.4 - Unauthenticated Simple Login Bypass via IP Address Spoofing
CVE-2010-1022
t3sec_saltedpw < 0.2.13 - Authentication Bypass
CVE-2010-0447
HP OpenView Performance Insight < 5.4 - Unauthenticated Remote Code Execution via Helpmanager Servlet
CVE-2010-0756
WikyBlog 1.7.3 rc2 - Session Fixation
CVE-2010-0554
Geo++ GNCASTER < 1.4.0.7 - Authentication Bypass via HTTP Digest Replay Attack
CVE-2010-0550
Geo++ GNCASTER < 1.4.0.7 - Improper Authentication via HTTP Basic Authentication Bypass
CVE-2010-0014
SSSD < 1.0.1 - Improper Authentication via Kerberos TGT Handling
CVE-2009-5116
McAfee LinuxShield <= 1.5.1 - Authenticated Privilege Escalation to Admin via Statistics Server
CVE-2009-0695
Wyse Device Manager 4.7.x - Unauthenticated Remote Command Execution via hagent.exe
CVE-2009-5083
IBM Tivoli Federated Identity Manager 6.2.0 - Authentication Bypass via OpenID OP-Identifier
CVE-2009-5077
CRE Loaded < 6.2.14 - Unauthenticated Authentication Bypass via PHP_SELF Manipulation
CVE-2009-5076
CRE Loaded < 6.2.14 - Unauthenticated Authentication Bypass via PATH_INFO Manipulation
CVE-2009-4987
Scripteen Free Image Hosting Script 2.3 - Unauthenticated Authentication Bypass via cookgid Cookie
CVE-2009-4929
Sweetphp Totalcalender - Authentication Bypass
CVE-2009-4927
WB News 2.1.2 - Unauthenticated Authentication Bypass via WBNEWS Cookie
Details
Vulnerabilities 4,376
Exploit Likelihood High