← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Stewart Howe
1Celerbb
Apr 23, 2026
Mar 9, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via special characters in the Username parameter, as demonstrated by an adm...Show more
login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via special characters in the Username parameter, as demonstrated by an admin'# parameter value.Show less
1Yourplace
1Yourplace
Apr 23, 2026
Mar 9, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in YourPlace before 1.0.1 has unknown impact and attack vectors, possibly related to improper authentication and the ability to upload arbitrary PHP code. NOTE: some of these details are obtain...Show more
Unspecified vulnerability in YourPlace before 1.0.1 has unknown impact and attack vectors, possibly related to improper authentication and the ability to upload arbitrary PHP code. NOTE: some of these details are obtained from third party information.Show less
2Cerberus
Webgroupmedia
2Cerberus Helpdesk
Cerberus Helpdesk
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2)...Show more
Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs.Show less
1Explay
1Explay Cms
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1.
1E Topbiz
1Link Back Checker
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin."
1Cisco
1Unified Meetingplace Web Conferencing
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
9.0 HIGH· v2
Unspecified vulnerability in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) (aka 7.0 MR1) allows remote attackers to bypass authentication and obta...Show more
Unspecified vulnerability in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) (aka 7.0 MR1) allows remote attackers to bypass authentication and obtain administrative access via a crafted URL.Show less
1Gwm
1Galatolo Webmanager
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the provenance of this information is unknown...Show more
Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Joovili
1Joovili
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username cookies for user priv...Show more
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username cookies for user privileges; (2) session_admin_id, session_admin_username, and session_admin cookies for admin privileges; and (3) session_staff_id, session_staff_username, and session_staff cookies for staff users.Show less
1Ibm
1Websphere Partner Gateway
Apr 23, 2026
Feb 22, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authenticated users to submit a crafted RosettaNet (aka RNIF) document to a...Show more
IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authenticated users to submit a crafted RosettaNet (aka RNIF) document to a backend application, related to (1) "altered service content" and (2) "digital signature foot-print."Show less
1Lenovo
1Veriface
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.
1Openssl
1Openssl
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack, a related...Show more
OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack, a related issue to CVE-2002-0970.Show less
1Ruby Lang
1Ruby
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly...Show more
ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.Show less
1Bux
1Bux.to Clone Script
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNick cookie to admin.
1Owentechkenya
1Owenpoll
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie.
1Mozilo
1Mozilowiki
Apr 23, 2026
Feb 13, 2009
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
1Mozilo
1Mozilocms
Apr 23, 2026
Feb 13, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
1Eyrie
1Pam Krb5
Apr 23, 2026
Feb 13, 2009
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to...Show more
Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.Show less
1Fail2ban
1Fail2ban
Apr 23, 2026
Feb 13, 2009
N/A· v4
N/A· v3
4.0 MEDIUM· v2
filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (forced authentication failures) via a crafted reverse-resolved DNS name (rhost) entry...Show more
filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (forced authentication failures) via a crafted reverse-resolved DNS name (rhost) entry that contains a substring that is interpreted as an IP address, a different vulnerability than CVE-2007-4321.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Feb 13, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify the system configuration.
1Goople Cms
1Goople Cms
Apr 23, 2026
Feb 11, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1.