← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1T Dreams
1Job Career Package
Apr 23, 2026
May 15, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin cookie to Login.
1Antony Lesuisse
1Ajaxterm
Apr 23, 2026
May 14, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it easier for remote attackers to (1) hijack a session or (2) cause a deni...Show more
ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it easier for remote attackers to (1) hijack a session or (2) cause a denial of service (session ID exhaustion) via a brute-force attack.Show less
1Squirrelmail
1Squirrelmail
Apr 23, 2026
May 14, 2009
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie.
1Teraway
1Filestream
Apr 23, 2026
May 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1.
1Teraway
1Livehelp
Apr 23, 2026
May 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie.
1Teraway
1Linktracker
Apr 23, 2026
May 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin cookie.
1Tribiq
1Tribiq Cms
Apr 23, 2026
May 11, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NOTE: a third party reports that the vendo...Show more
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NOTE: a third party reports that the vendor disputes the existence of this issueShow less
1Igniterealtime
1Openfire
Apr 23, 2026
May 11, 2009
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change...Show more
Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.Show less
1Igniterealtime
1Openfire
Apr 23, 2026
May 11, 2009
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd...Show more
The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.Show less
1Kalptarudemos
1Php Site Lock
Apr 23, 2026
May 7, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, login_name, user_id, and user_type cookies to certain values.
1Agtc
1Agtc Myshop
Apr 23, 2026
May 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto."
1Xigla
1Absolute Control Panel Xe
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "lvl=1&userid=1."
1Rens Rikkerink
1Fungamez
Apr 23, 2026
Apr 29, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie parameter.
1Hypersilence
1Silentum Loginsys
Apr 23, 2026
Apr 28, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's username.
1Plone
1Plonepas
Apr 23, 2026
Apr 23, 2009
N/A· v4
N/A· v3
6.0 MEDIUM· v2
The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecifi...Show more
The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.Show less
1Shock Therapy
1Rsmscript
Apr 23, 2026
Apr 22, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.p...Show more
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.Show less
1Toddwoolums
1Asp Download
Apr 23, 2026
Apr 21, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct request.
1Mark Girling
1Myshoutpro
Apr 23, 2026
Apr 21, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1.
1Turnkeyforms
1Entertainment Portal
Apr 23, 2026
Apr 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cookie to Administrator.
1Uochm
1Justlistit
Apr 23, 2026
Apr 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (...Show more
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) start.php, (2) aktivitet.php, (3) prop_aktivitet.php, (4) kategorier.php, (5) konfig.php, (6) security.php, (7) manual.php, and possibly (8) index.php.Show less