CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,376 vulnerabilities with CWE-287
CVE-2009-4909
dootzky oBlog - Unauthenticated Brute-Force Password Guessing via admin/index.php
CVE-2009-4879
Novell Access Manager < 3.1 SP1 - Authentication Bypass via X.509 Authentication
CVE-2009-4843
ToutVirtual VirtualIQ Pro - Unauthenticated Remote Command Execution via JBoss Console
CVE-2009-4830
OpenX 2.8.1 and 2.8.2 - Authentication Bypass
CVE-2009-4821
D-Link DIR-615 3.10NA - Unauthenticated Admin Password Change via apply.cgi
CVE-2009-4808
Graugon PHP Article Publisher 1.0 - Unauthenticated Authentication Bypass via g_admin Cookie
CVE-2009-4806
Digital Interchange Document Library 1.0.1 - Unauthenticated Administrator Credential Modification via save_user.asp
CVE-2009-4801
EZ-Blog Beta 1 - Unauthenticated Arbitrary Post Creation and Deletion
CVE-2009-2936
Varnish < 2.1.0 - Unauthenticated Remote Code Execution via CLI vcl.inline Directive
CVE-2009-4675
Mole Group Gastro Portal - Info Disclosure
CVE-2009-4671
RoomPHPlanning 1.6 - Unauthenticated Authentication Bypass via Cookie Manipulation
CVE-2009-4670
RoomPHPlanning 1.6 - Unauthenticated Arbitrary User and Room Deletion via admin/delitem.php
CVE-2009-4657
Xerver 4.32 - Unauthenticated Administrator Access via Port 32123
CVE-2009-4584
dB Masters Multimedia Links Directory 3.1.3 - Auth Bypass
CVE-2009-4447
Jax Guestbook 3.5.0 - Unauthenticated Authentication Bypass via Direct Admin Endpoint Access
CVE-2009-4409
Internet Initiative Japan SEIL/B1 <2.52 - Auth Bypass
CVE-2009-4367
Sitecore Staging Module <5.4.0 - Auth Bypass
CVE-2009-3027
Symantec Veritas Products - Unauthenticated Remote Code Execution via Crafted Data to TCP Port 14300
CVE-2009-2505
Microsoft Windows Vista/Server 2008 SP2 - RCE
CVE-2009-4232
Kide Shoutbox (com_kide) <0.4.6 - Auth Bypass
CVE-2009-4151
Best Practical Solutions RT <3.6.9, <3.8.5 - Session Fixation
CVE-2009-3585
Bestpractical RT - Authentication Bypass
CVE-2009-4128
GNU GRUB 2 1.97 - Improper Authentication via Password Length Bypass
CVE-2009-4095
myPhile 1.2.1 - Unauthenticated Authentication Bypass via Empty Password
CVE-2009-4089
telepark.wiki <2.4.23 - Auth Bypass
Details
Vulnerabilities 4,376
Exploit Likelihood High