When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,376 vulnerabilities with CWE-287
CVE-2009-2642
Desi Short URL Script 1.0 - Auth Bypass
CVE-2009-2481
Six Apart Movable Type <4.261 - Auth Bypass
CVE-2009-2334
WordPress < 2.8.1 - Unauthenticated Sensitive Information Exposure via Plugin Configuration
CVE-2009-2422
CRITICAL
Ruby on Rails < 2.3.3 - Authentication Bypass via Invalid Username
CVSS 9.8
CVE-2009-2382
CRITICAL
phpMyBlockchecker 1.0.0055 - Auth Bypass
CVSS 9.8
CVE-2009-2328
KerviNet Forum < 1.1 - Unauthenticated SQL Injection and Arbitrary Account Deletion via del_user_id Parameter
CVE-2009-2257
Netgear DG632 3.4.0_ap - Auth Bypass
CVE-2009-2255
Zen Cart <= 1.3.8a - Unauthenticated Arbitrary File Upload via record_company_image Parameter
CVE-2009-2233
AWScripts.com Gallery Search Engine 1.5 - Auth Bypass
CVE-2009-2231
MIDAS 1.43 - Unauthenticated Authentication Bypass via Admin Cookie
CVE-2009-2168
CRITICAL
EgyPlus 7ammel <1.0.1 - Auth Bypass
CVSS 9.8
CVE-2009-2159
TorrentTrader Classic 1.09 - Info Disclosure
CVE-2009-2117
phPortal 1.0 - Unauthenticated Authentication Bypass via kulladi Cookie
CVE-2009-1390
Mutt 1.5.19 - Improper TLS Certificate Chain Validation
CVE-2009-2072
Apple Safari - Improper Authentication via Cached Certificate Spoofing
CVE-2009-2071
Google Chrome < 1.0.154.53 - Improper Authentication via Cached Certificate
CVE-2009-2070
Opera Browser - Certificate Spoofing via Cached Proxy Response
CVE-2009-2069
Microsoft Internet Explorer <8 - Info Disclosure
CVE-2009-2068
Opera - Improper Authentication
CVE-2009-2067
Opera < 9.22 - Improper Authentication via HTTPS Frame Injection
CVE-2009-2066
Apple Safari - Cross-Site Scripting via HTTPS IFrame Script Injection
CVE-2009-2065
Firefox < 3.0.9 - Improper Authentication via HTTP-Intended-but-HTTPS-Loadable Pages
CVE-2009-2064
Microsoft Internet Explorer 8 - XSS
CVE-2009-2063
Opera < 9.25 - Man-in-the-Middle Script Execution via 3xx CONNECT Response
CVE-2009-2062
Apple Safari < 3.2.2 - Man-in-the-Middle Script Execution via 3xx CONNECT Response
Details
Vulnerabilities
4,376
Exploit Likelihood
High