Vulnerabilities (CVE)

Filtered by CWE-287
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6723 1 Turnkeyforms 1 Entertainment Portal 2017-09-29 7.5 HIGH N/A
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cookie to Administrator.
CVE-2008-6718 1 Uochm 1 Justbookit 2017-09-29 7.5 HIGH N/A
U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) user_manual.php, (2) user_config.php, (3) user_kundnamn.php, (4) user_kundlista.php, (5) user_aktiva_kunder.php, (6) database.php, and possibly (7) index.php.
CVE-2008-6738 1 Mark Girling 1 Myshoutpro 2017-09-29 7.5 HIGH N/A
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1.
CVE-2008-6912 1 Zeeways 1 Shaadiclone 2017-09-29 7.5 HIGH N/A
Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin/home.php.
CVE-2008-6864 1 Xigla 1 Absolute Live Support .net 2017-09-29 7.5 HIGH N/A
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2008-6863 1 Xigla 1 Absolute Form Processor.net 2017-09-29 7.5 HIGH N/A
Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2008-6739 1 Toddwoolums 1 Asp Download 2017-09-29 7.5 HIGH N/A
Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct request.
CVE-2008-6862 1 Xigla 1 Absolute Content Rotator 2017-09-29 7.5 HIGH N/A
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2008-6861 1 Xigla 1 Absolute Newsletter 2017-09-29 7.5 HIGH N/A
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2008-6743 1 Shock-therapy 1 Rsmscript 2017-09-29 7.5 HIGH N/A
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.
CVE-2008-6860 1 Xigla 1 Absolute Poll Manager Xe 2017-09-29 7.5 HIGH N/A
Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2008-6859 1 Xigla 1 Absolute Control Panel Xe 2017-09-29 7.5 HIGH N/A
Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2008-6763 1 Hypersilence 1 Silentum Loginsys 2017-09-29 7.5 HIGH N/A
login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's username.
CVE-2008-6804 1 Tribiq 1 Tribiq Cms 2017-09-29 7.5 HIGH N/A
** DISPUTED ** Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NOTE: a third party reports that the vendor disputes the existence of this issue.
CVE-2008-6858 1 Xigla 1 Absolute Banner Manager.net 2017-09-29 7.5 HIGH N/A
Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2008-6857 1 Xigla 1 Absolute Podcast.net 2017-09-29 7.5 HIGH N/A
Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2008-6856 1 Xigla 1 Absolute News Manager.net 2017-09-29 7.5 HIGH N/A
Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2008-6855 1 Xigla 1 Absolute News Feed 2017-09-29 7.5 HIGH N/A
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.
CVE-2008-6854 1 Xigla 1 Absolute Faq Manager .net 2017-09-29 7.5 HIGH N/A
Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CVE-2008-7027 1 Libra File Manager 1 Php Filemanager 2017-09-29 7.5 HIGH N/A
Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1.
CVE-2008-6815 1 Myktools 1 Myktools 2017-09-29 5.0 MEDIUM N/A
mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a direct request, and then sending an unspecified request to the download page for the backup.
CVE-2008-7028 1 Aves 1 Rpg Board 2017-09-29 7.5 HIGH N/A
RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep4u cookie to a certain value.
CVE-2008-7041 1 Ajsquare 1 Aj Classifieds 2017-09-29 7.5 HIGH N/A
AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.
CVE-2008-7045 1 Ajsquare 1 Free Polling Script 2017-09-29 6.4 MEDIUM N/A
AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to admin/resetvote.php.
CVE-2008-7019 1 Esqlanelapse 1 Esqlanelapse 2017-09-29 7.5 HIGH N/A
Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enombre and (2) euri cookies.
CVE-2008-6716 1 Preprojects 1 Pre Ads Portal 2017-09-29 7.5 HIGH N/A
homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to have an unspecified impact via a direct request.
CVE-2008-7047 1 Natterchat 1 Natterchat 2017-09-29 7.5 HIGH N/A
NatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete rooms and messages via a direct request to admin/home.asp.
CVE-2008-7051 1 Ajsquare 1 Aj Article 2017-09-29 7.5 HIGH N/A
AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesuspend.php, (4) site.php, (5) statistics.php, (6) mail.php, (7) category.php, (8) subcategory.php, (9) changepassword.php, (10) polling.php, and (11) logo.php in admin/.
CVE-2008-7086 1 Maianscriptworld 1 Maian Greetings 2017-09-29 7.5 HIGH N/A
Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to admin.
CVE-2008-7124 1 Zkup 1 Zkup 2017-09-29 7.5 HIGH N/A
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as demonstrated by adding a new administrator.
CVE-2008-7007 1 Phpversion 1 Php Vx Guestbook 2017-09-29 7.5 HIGH N/A
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name and (2) admin_pass cookie values to 1.
CVE-2008-6667 1 Marc Melvin 1 A\+ Php Scripts News Management System 2017-09-29 7.5 HIGH N/A
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1.
CVE-2008-7156 1 Ekinboard 1 Ekinboard 2017-09-29 6.8 MEDIUM N/A
EkinBoard 1.1.0 and earlier, when register_globals is enabled, allows remote attackers to bypass authorization and gain administrator privileges by setting the _groups[] parameter to 2, as demonstrated via backup.php.
CVE-2008-7179 1 Otmanager 1 Otmanager Cms 2017-09-29 7.5 HIGH N/A
OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN_Hora, ADMIN_Logado, and ADMIN_Nome cookies to certain values, as reachable in Admin/index.php.
CVE-2009-0030 1 Squirrelmail 1 Squirrelmail 2017-09-29 6.5 MEDIUM N/A
A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.
CVE-2008-6664 1 Yarck 1 Sh-news 2017-09-29 7.5 HIGH N/A
action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.
CVE-2008-6581 1 Phpaddedit 1 Phpaddedit 2017-09-29 7.5 HIGH N/A
login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.
CVE-2008-6553 1 Impliedbydesign 1 Micro-cms 2017-09-29 7.5 HIGH N/A
microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an administrator, which allows remote attackers to (1) create administrative accounts via an add_admin action, (2) remove administrative accounts via a delete_admin action, and (3) modify administrative passwords via a change_password action.
CVE-2008-6411 1 Explay 1 Explay Cms 2017-09-29 7.5 HIGH N/A
Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1.
CVE-2008-6307 1 E-topbiz 1 Link Back Checker 2017-09-29 7.5 HIGH N/A
E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin."
CVE-2008-7006 1 Phpversion 1 Php Vx Guestbook 2017-09-29 5.0 MEDIUM N/A
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php.
CVE-2008-6965 1 Aj Square 1 Aj Auction 2017-09-29 7.5 HIGH N/A
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a direct request to (1) site.php, (2) auction.php, (3) mail.php, (4) fee_setting.php, (5) earnings.php, (6) insertion_fee_settings.php, (7) custom_category.php, (8) subcategory.php, (9) category.php, (10) report.php, (11) store_manager.php, and (12) choose_sell_format.php in admin/, and possibly other vectors.
CVE-2009-0642 1 Ruby-lang 1 Ruby 2017-09-29 6.8 MEDIUM N/A
ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.
CVE-2008-5125 1 Castillocentral 1 Ccleague 2017-09-29 6.8 MEDIUM N/A
admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin.
CVE-2008-6162 1 Bux 1 Bux.to Clone Script 2017-09-29 7.5 HIGH N/A
Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNick cookie to admin.
CVE-2008-6143 1 Owentechkenya 1 Owenpoll 2017-09-29 7.5 HIGH N/A
OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie.
CVE-2008-6118 1 Goople Cms 1 Goople Cms 2017-09-29 7.5 HIGH N/A
win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1.
CVE-2008-6092 1 Phpscripts 1 Ranking-script 2017-09-29 7.5 HIGH N/A
phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie.
CVE-2008-6009 1 Sg Real Estate Portal 1 Sg Real Estate Portal 2017-09-29 7.5 HIGH N/A
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.
CVE-2008-5880 1 Gobbl 1 Gobbl Cms 2017-09-29 7.5 HIGH N/A
admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok".