← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wholehogsoftware
1Password Protect
Apr 23, 2026
Feb 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.
1Wholehogsoftware
1Ware Support
Apr 23, 2026
Feb 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.
1Simpleircbot
1Simpleircbot
Apr 23, 2026
Feb 10, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in SimpleIrcBot before 1.0 Stable has unknown impact and attack vectors related to an "auth vulnerability."
1Phpscripts
1Ranking Script
Apr 23, 2026
Feb 9, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie.
1Goahead
1Goahead Webserver
Apr 23, 2026
Feb 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-16...Show more
The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-1603.Show less
1Interspire
1Shopping Cart
Apr 23, 2026
Feb 3, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative access by reusing the RememberToken cookie a...Show more
The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative access by reusing the RememberToken cookie after a failed admin login attempt.Show less
1Xt Commerce
1Xt Commerce
Apr 23, 2026
Feb 3, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter.
2Bluepage
Iss Oberlausitz
2Bluepage Cms
Bluepage Cms
Mar 23, 2026
Feb 3, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
1Redhat
2 Dogtag Certificate System
Certificate System
Apr 23, 2026
Jan 30, 2009
N/A· v4
N/A· v3
6.0 MEDIUM· v2
The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enrollment did not use t...Show more
The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enrollment did not use the hardware key, which allows remote authenticated users with enrollment privileges to bypass intended authentication policies by performing enrollment with a software key.Show less
1Sg Real Estate Portal
1Sg Real Estate Portal
Apr 23, 2026
Jan 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.
1Asp Project
1Asp Project
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.
1Phpicalendar
1Phpicalendar
Apr 23, 2026
Jan 26, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content...Show more
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.Show less
1Impresscms
1Impresscms
Apr 23, 2026
Jan 23, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
1Typo3
1Typo3
Apr 23, 2026
Jan 22, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1...Show more
Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1) frontend and (2) backend authentication.Show less
1Nukevietcms
1Nukeviet
Apr 23, 2026
Jan 22, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provenance of this information is unknown; the details are obtained solely fro...Show more
Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Squirrelmail
1Squirrelmail
Apr 23, 2026
Jan 21, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic ci...Show more
A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.Show less
1Trend Micro
3Internet Security 2007
Internet Security 2008Officescan
Apr 23, 2026
Jan 21, 2009
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Trend Micro Personal Firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, relies o...Show more
The Trend Micro Personal Firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, relies on client-side password protection implemented in the configuration GUI, which allows local users to bypass intended access restrictions and change firewall settings by using a modified client to send crafted packets.Show less
1Erlang
1Erlang
Apr 23, 2026
Jan 15, 2009
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed S...Show more
lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of crypto_drv.c, and thus "this report is invalid.Show less
1Perl Openssl
1Libcrypt Openssl Dsa Perl
Apr 23, 2026
Jan 15, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed...Show more
libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.Show less
1Llnl
1Slurm
Apr 23, 2026
Jan 15, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote at...Show more
plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.Show less