CWE-425

Direct Request ('Forced Browsing')

Parent: CWE-862 - Missing Authorization

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

235 vulnerabilities with CWE-425
CVE-2018-19143 MEDIUM
OTRS <4.0.33-6.0.13 - Privilege Escalation
CVSS 6.5
CVE-2018-19109 HIGH
tianti 2.3 - Authenticated Permission Bypass via Direct Request to Column List Endpoint
CVSS 8.8
CVE-2018-16706 HIGH
LG SuperSign CMS - Unauthenticated Denial of Service via /qsr_server/device/reboot Endpoint
CVSS 7.5
CVE-2018-3774 CRITICAL
url-parse < 1.4.3 - Server-Side Request Forgery via Incorrect Hostname Parsing
CVSS 10.0
CVE-2018-7526 HIGH
TotalAlert Web App <v4107600010.23 - Info Disclosure
CVSS 7.5
CVE-2018-11346 MEDIUM
ASUSTOR AS6202T ADM 3.1.0.RFQ3 - Info Disclosure
CVSS 4.3
CVE-2018-0267 MEDIUM
Cisco Unified Communications Manager - Authenticated Exposure of Sensitive Information via Web Interface
CVSS 6.5
CVE-2018-0266 MEDIUM
Cisco Unified Communications Manager - Authenticated Exposure of Sensitive Configuration Data via Web Interface
CVSS 4.3
CVE-2018-0198 MEDIUM
Cisco Unified Communications Manager - Info Disclosure
CVSS 5.3
CVE-2018-0140 MEDIUM
Cisco Email Security Appliance - Unauthorized Spam Quarantine Access via Browser Manipulation
CVSS 6.5
CVE-2018-6624 CRITICAL
OMRON NS Series Firmware 1.1-1.3 - Unauthenticated Authentication Bypass via Direct Request
CVSS 9.8
CVE-2018-0105 MEDIUM
Cisco Unified Communications Manager - Unauthenticated Exposure of Sensitive Information via Database Table Access
CVSS 5.3
CVE-2017-17736 CRITICAL
Kentico - Installer Privilege Escalation
CVSS 9.8
CVE-2017-14993 HIGH
OXID eShop <6.0.0 RC3, <4.10.6, <4.9.11 - Info Disclosure
CVSS 7.5
CVE-2017-15235 HIGH
Horde Groupware <5.2.21 - Auth Bypass
CVSS 7.5
CVE-2017-14244 CRITICAL
iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 - Auth Bypass
CVSS 9.8
CVE-2017-10833 CRITICAL
Dokodemo eye Smart HD <1.0.3.1000 - Auth Bypass
CVSS 9.1
CVE-2017-2161 LOW
FlashAir SD-WE <W-03 and SD-WD/WC <W-02 - Authenticated Unauthorized Data Access
CVSS 3.5
CVE-2017-2143 MEDIUM
CS-Cart Japanese Edition <4.3.10-jp-1 - Auth Bypass
CVSS 5.3
CVE-2017-2139 MEDIUM
CS-Cart Japanese Edition <4.3.10 - Auth Bypass
CVSS 5.3
CVE-2017-2486 MEDIUM
Safari < 10.1 and iPhone OS < 10.3 - Address Bar Spoofing via WebKit
CVSS 6.5
CVE-2016-1000111 MEDIUM
Twisted < 16.3.1 - Remote Proxy Redirection via HTTP_PROXY Environment Variable
CVSS 5.3
CVE-2015-1313 MEDIUM
JetBrains TeamCity <9.0.2 - Auth Bypass
CVSS 6.5
CVE-2015-2873
Trend Micro Deep Discovery Inspector <3.5.1477-<3.8.1263 - Info Dis...
CVE-2005-1892
FlatNuke < 2.5.3 - Denial of Service and Information Disclosure via Direct Request
Details
Vulnerabilities 235