When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,376 vulnerabilities with CWE-287
CVE-2009-2060
Google Chrome < 1.0.154.53 - SSL Tampering via Proxy CONNECT Response
CVE-2009-2059
Opera < 9.25 - Cross-Site Scripting via Proxy CONNECT Response
CVE-2009-2058
Apple Safari < 3.2.2 - Cross-Site Scripting via Proxy CONNECT Response
CVE-2009-2057
Microsoft Internet Explorer <8 - SSRF
CVE-2009-1836
Firefox < 3.0.10 - SSL Tampering via HTTP Host Header
CVE-2009-2040
Grestul 1.2 - Unauthenticated Authentication Bypass and Administrative Account Creation via Direct Request
CVE-2009-1122
Microsoft Internet Information Services 5.0 - Authentication Bypass via WebDAV URL Decoding
CVE-2009-1535
Internet Information Services 5.1 and 6.0 - Authentication Bypass via Unicode %c0%af URI Obfuscation
CVE-2009-2003
Ascad Networks Password Protector SD <1.3.1 - Auth Bypass
CVE-2009-1905
IBM DB2 <8.FP17, <9.1.FP7, <9.5.FP4 - Auth Bypass
CVE-2009-1854
Million Dollar Text Links 1.0 - Unauthenticated Authentication Bypass via userid Cookie
CVE-2009-1826
myGesuad 0.9.14 - Authenticated User Account Enumeration via Find Action
CVE-2009-1825
myColex 1.4.2 - Authenticated User Account Enumeration via admuser.php Find Action
CVE-2009-1384
pam-krb5 2.2.14-2.3.4 - Username Enumeration via Differential Password Prompts
CVE-2009-1754
Android 1.5-1.5 CRB42 - Improper Authentication via Shared User ID Request
CVE-2009-1670
TCPDB 3.8 - Unauthenticated Admin Account Creation via user/index.php
CVE-2009-1664
Easy Scripts Answer and Question Script - Unauthenticated Password Change via myaccount.php
CVE-2009-1638
Techno Dreams Job Career Package 3.0 - Unauthenticated Authentication Bypass via JobCareerAdmin Cookie
CVE-2009-1629
AjaxTerm < 0.10 - Session Hijacking and Denial of Service via Predictable Session ID
CVE-2009-1580
SquirrelMail < 1.4.18 - Session Fixation via Crafted Cookie
CVE-2009-1619
Teraway FileStream 1.0 - Unauthenticated Authentication Bypass via twFSadmin Cookie
CVE-2009-1618
Teraway LiveHelp 2.0 - Unauthenticated Authentication Bypass via TWLHadmin Cookie
CVE-2009-1617
Teraway LinkTracker 1.0 - Unauthenticated Authentication Bypass via Cookie Manipulation
CVE-2009-1596
MEDIUM
Openfire < 3.6.5 - Authenticated Password Change Policy Bypass via IQ Packet
CVSS 6.5
CVE-2009-1595
Openfire < 3.6.4 - Authenticated Password Change via Modified Username Element
Details
Vulnerabilities
4,376
Exploit Likelihood
High