← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Natterchat
1Natterchat
Apr 23, 2026
Aug 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
NatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete rooms and messages via a direct request to admin/home.asp.
1Ajsquare
1Free Polling Script
Apr 23, 2026
Aug 24, 2009
N/A· v4
N/A· v3
6.4 MEDIUM· v2
AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/newpoll.php, a different vector than CVE-2008-7045. NOTE: the provenance...Show more
AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/newpoll.php, a different vector than CVE-2008-7045. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Ajsquare
1Free Polling Script
Apr 23, 2026
Aug 24, 2009
N/A· v4
N/A· v3
6.4 MEDIUM· v2
AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to admin/resetvote.php.
1Ajsquare
1Aj Classifieds
Apr 23, 2026
Aug 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.
1Tiki
1Tikiwiki Cms/groupware
Apr 23, 2026
Aug 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Internet Explorer "Remember Me" feature. NOTE: some of these details are o...Show more
TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Internet Explorer "Remember Me" feature. NOTE: some of these details are obtained from third party information.Show less
1Aves
1Rpg Board
Apr 23, 2026
Aug 21, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep4u cookie to a certain value.
1Libra File Manager
1Php Filemanager
Apr 23, 2026
Aug 21, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1.
1Esqlanelapse
1Esqlanelapse
Apr 23, 2026
Aug 21, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enombre and (2) euri cookies.
1Hyperstop
1Web Host Directory
Apr 23, 2026
Aug 19, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/db.
1Phpversion
1Php Vx Guestbook
Apr 23, 2026
Aug 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name and (2) admin_pass cookie values to 1.
1Phpversion
1Php Vx Guestbook
Apr 23, 2026
Aug 19, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php.
1Parallels
1Plesk
Apr 23, 2026
Aug 19, 2009
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname...Show more
Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3.Show less
1Adobe
1Coldfusion
Apr 23, 2026
Aug 18, 2009
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
1Ibm
1Websphere Application Server
Apr 23, 2026
Aug 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single Sign-on (SSO) and disableSecurityPreInvokeOnFilters are configured, allo...Show more
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single Sign-on (SSO) and disableSecurityPreInvokeOnFilters are configured, allows remote attackers to bypass authentication via a request for a "secure URL," related to a certain invokefilterscompatibility property.Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Aug 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass...Show more
The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Aug 13, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions an...Show more
The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors.Show less
1Aj Square
1Aj Auction
Apr 23, 2026
Aug 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a di...Show more
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a direct request to (1) site.php, (2) auction.php, (3) mail.php, (4) fee_setting.php, (5) earnings.php, (6) insertion_fee_settings.php, (7) custom_category.php, (8) subcategory.php, (9) category.php, (10) report.php, (11) store_manager.php, and (12) choose_sell_format.php in admin/, and possibly other vectors.Show less
1Cms.maury91
1Maurycms
Apr 23, 2026
Aug 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
MauryCMS 0.53.2 and earlier does not require administrative authentication for Editors/fckeditor/editor/filemanager/browser/default/browser.html, which allows remote attackers to upload arbitrary files via a direct reque...Show more
MauryCMS 0.53.2 and earlier does not require administrative authentication for Editors/fckeditor/editor/filemanager/browser/default/browser.html, which allows remote attackers to upload arbitrary files via a direct request.Show less
1Collabtive
1Collabtive
Apr 23, 2026
Aug 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via unspecified vectors associated with the added mode in a users action to admin.php.
1Turnkeyforms
1Web Hosting Directory
Apr 23, 2026
Aug 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie to 1 or (2) gain privileges as another user by setting the logged cooki...Show more
TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie to 1 or (2) gain privileges as another user by setting the logged cookie to the target username.Show less