When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,376 vulnerabilities with CWE-287
CVE-2008-5692
Ipswitch WS_FTP Server Manager <6.1.1 - Auth Bypass
CVE-2008-5686
IBM Tivoli Provisioning Manager <5.1.1.1 IF0006 - RCE
CVE-2008-5558
Asterisk Open Source 1.2.26-1.2.30.3 & Business Edition B.2.3.5-B.2.5.5 - DoS via Realtime IAX2 Auth
CVE-2008-4223
Apple Mac OS X Server < 10.5.6 - Podcast Producer Authentication Bypass
CVE-2008-5576
scssboard 1.0-1.12 - Unauthenticated Authentication Bypass via current_user[users_level] Parameter
CVE-2008-5575
Pro Clan Manager <0.4.2 - Info Disclosure
CVE-2008-5497
BandSite CMS 1.1.4 - Unauthenticated Authentication Bypass via login_auth Cookie
CVE-2008-4032
Microsoft Office SharePoint Server and Search Server - Improper Authentication and Authorization
CVE-2008-5407
Symantec Backup Exec 11.0-12.5 - Authentication Bypass & Arbitrary File Read/Delete
CVE-2008-5355
Sun JDK and JRE - Remote Code Execution via Unverified Java Update
CVE-2008-5296
Gallery <1.5.10, <1.6-RC3 - Auth Bypass
CVE-2008-5221
wportfolio < 0.3 - Unauthenticated Admin Password Change via account_save Action
CVE-2008-5219
VideoScript <4.0.1.50 - Auth Bypass
CVE-2008-5158
Client Software WinCom LPD Total <3.0.2.623 - Auth Bypass
CVE-2008-5125
CCleague Pro 1.2 - Unauthenticated Authentication Bypass via Type Cookie
CVE-2008-5124
JSCAPE Secure FTP Applet < 4.8.0 - SSH Host Key Verification Bypass
CVE-2008-5065
Easy-script Tlguesbook - Authentication Bypass
CVE-2008-5022
Firefox 2.0-2.0.0.17 and 3.0-3.0.3 - Same-Origin Policy Bypass via nsXMLHttpRequest Event Listeners
CVE-2008-4037
Microsoft Windows - Remote Code Execution via SMB Credential Reflection
CVE-2008-5042
Zeeways PhotoVideoTube < 1.1 - Unauthenticated Authentication Bypass via Direct Admin Request
CVE-2008-5040
Graphiks MyForum 1.3 - Unauthenticated Authentication Bypass via Cookie Manipulation
CVE-2008-4784
aflog 1.01 - Unauthenticated Authentication Bypass via aflog_auth_a Cookie
CVE-2008-4783
tlAds 1.0 - Unauthenticated Authentication Bypass via tlAds_login Cookie
CVE-2008-4752
TlNews 2.2 - Unauthenticated Authentication Bypass via tlNews_login Cookie
CVE-2008-4722
Sun Integrated Lights-Out Manager 2.0.1.5-2.0.4.26 - Authenticated Denial of Service and Unspecified Impact
Details
Vulnerabilities
4,376
Exploit Likelihood
High