When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,376 vulnerabilities with CWE-287
CVE-2008-3815
Cisco ASA/PX <7.0.8.3-8.1.1.13 - Auth Bypass
CVE-2008-4721
PHP Jabbers Post Comment 3.0 - Unauthenticated Administrative Access via PostCommentsAdmin Cookie
CVE-2008-4714
Atomic Photo Album 1.1.0 pre4 - Authentication Bypass via Cookie Manipulation
CVE-2008-4708
bbzl.php 0.92 - Unauthenticated Authentication Bypass via phorum_admin_session Cookie
CVE-2008-4689
Mantis < 1.1.3 - Session Hijacking via Unset Session Cookie
CVE-2008-4679
IBM WebSphere Application Server 6.0.2-6.0.2.30 and 6.1-6.1.0.18 - Improper Certificate Revocation Validation
CVE-2008-4649
Elxis CMS 2008.1 revision 2204 - Session Fixation via PHPSESSID Parameter
CVE-2008-4622
phpfastnews 1.0.0 - Unauthenticated Authentication Bypass via Cookie Manipulation
CVE-2008-4614
PortalApp 4.0 - Unauthenticated Forum and Content Management via forums.asp and content.asp
CVE-2008-4576
Linux kernel < 2.6.25.18 - Denial of Service via SCTP INIT-ACK
CVE-2008-3466
Microsoft Host Integration Server 2000, 2004, 2006 - Unauthenticated Remote Code Execution via SNA RPC Message
CVE-2008-4515
Blue Coat K9 Web Protection 4.0.230 Beta - Unauthenticated Authentication Bypass via JavaScript Disabling
CVE-2008-3814
Cisco Unity <4.2.1-5.0.1-7.0.2 - Auth Bypass
CVE-2008-4427
Phlatline Personal Information Manager < 1.0 - Unauthenticated Arbitrary Password Change
CVE-2008-4319
Libra PHP File Manager < 1.18 - Improper Authentication Bypass via Query String Parameters
CVE-2008-4244
Rianxosencabos CMS 0.9 - Unauthenticated Authentication Bypass via Cookie Manipulation
CVE-2008-4146
Addalink < 1.0 - Improper Authentication
CVE-2008-4167
ezphotogallery 2.1 - Unauthenticated Administrator Account Manipulation via useradmin.php
CVE-2008-3611
Apple Mac OS X 10.4.11 - Auth Bypass
CVE-2008-3610
Apple Mac OS X 10.5-10.5.4 - Auth Bypass
CVE-2008-4081
Stash 1.0.3 - Unauthenticated Authentication Bypass via bsm Cookie
CVE-2008-3905
Ruby <1.8.6-p287, <1.8.7-p72, <1.9-r18423 - SSRF
CVE-2008-3891
Google Apps - SAML Authentication Impersonation via Missing Request Identifier and Recipient Field
CVE-2008-3738
CRITICAL
SpaceTag LacoodaST <2.1.3 - Info Disclosure
CVSS 9.1
CVE-2008-3729
MicroWorld Technologies MailScan <5.6.a - Auth Bypass
Details
Vulnerabilities
4,376
Exploit Likelihood
High