← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tech Logic
1Tlnews
Apr 23, 2026
Oct 27, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login cookie to admin.
1Sun
37Blade 6000 Modular System With Chassis
Blade 6048 Modular System With ChassisBlade 8000 Modular System+34 more
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
9.0 HIGH· v2
Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot)...Show more
Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors.Show less
1Cisco
2Asa 5500
Pix
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)3, 7.1 before 7.1(2)78, 7.2 before 7.2(4)16, 8.0 before 8.0(4)6, and 8.1 before 8.1(1)13, whe...Show more
Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)3, 7.1 before 7.1(2)78, 7.2 before 7.2(4)16, 8.0 before 8.0(4)6, and 8.1 before 8.1(1)13, when configured as a VPN using Microsoft Windows NT Domain authentication, allows remote attackers to bypass VPN authentication via unknown vectors.Show less
1Php Jabbers
1Post Comment
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged."
1Atomic Photo Album
1Atomic Photo Album
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified coo...Show more
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.Show less
1Sylvain Pasquet
1Bbzl.php
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1.
1Mantis
1Mantis
Apr 23, 2026
Oct 22, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
1Ibm
1Websphere Application Server
Apr 23, 2026
Oct 22, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), doe...Show more
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), does not call the setRevocationEnabled method on the PKIXBuilderParameters object, which prevents the "Java security method" from checking the revocation status of X.509 certificates and allows remote attackers to bypass intended access restrictions via a SOAP message with a revoked certificate.Show less
1Elxis
1Elxis Cms
Apr 23, 2026
Oct 22, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
1Phpfastnews
1Phpfastnews
Apr 23, 2026
Oct 21, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by setting the fn-loggedin cookie to 1.
1Portalapp
1Portalapp
Apr 23, 2026
Oct 20, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topics, and replies.
1Linux
1Linux Kernel
Apr 23, 2026
Oct 15, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active...Show more
sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires.Show less
1Microsoft
3Host Integration Server 2000
Host Integration Server 2004Host Integration Server 2006
Apr 23, 2026
Oct 15, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA...Show more
Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."Show less
1Blue Coat Systems
1K9 Web Protection
Apr 23, 2026
Oct 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Blue Coat K9 Web Protection 4.0.230 Beta relies on client-side JavaScript as a protection mechanism, which allows remote attackers to bypass authentication and access the (1) summary, (2) detail, (3) overrides, and (4) p...Show more
Blue Coat K9 Web Protection 4.0.230 Beta relies on client-side JavaScript as a protection mechanism, which allows remote attackers to bypass authentication and access the (1) summary, (2) detail, (3) overrides, and (4) pwemail pages by disabling JavaScript.Show less
1Cisco
1Unity
Apr 23, 2026
Oct 8, 2008
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to bypass a...Show more
Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to bypass authentication and read or modify system configuration parameters by going to a specific link more than once.Show less
1Phlatline
1Personal Information Manager
Apr 23, 2026
Oct 3, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows remote attackers to change arbitrary passwords.
1Libra File Manager
1Php Filemanager
Apr 23, 2026
Sep 29, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by ins...Show more
fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.Show less
1Rianxosencabos Cms
1Rianxosencabos Cms
Apr 23, 2026
Sep 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1.
1Addalink
1Addalink
Apr 23, 2026
Sep 24, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field.
1Ezphotogallery
1Ezphotogallery
Apr 23, 2026
Sep 22, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account.