← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mozilla
2Firefox
Seamonkey
Apr 23, 2026
Mar 27, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easie...Show more
Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.Show less
1Zyxel
3Prestige 660
Prestige 661Zynos
Apr 23, 2026
Mar 26, 2008
N/A· v4
N/A· v3
4.0 MEDIUM· v2
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain authentication data by making direct HTTP requests and then readi...Show more
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain authentication data by making direct HTTP requests and then reading the HTML source, as demonstrated by a request for (1) RemMagSNMP.html, which discloses SNMP communities; or (2) WLAN.html, which discloses WEP keys.Show less
1Gallarific
1Gallarific
Apr 23, 2026
Mar 24, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Gallarific Free Edition 1.1 does not require authentication for (1) photos.php, (2) comments.php, and (3) gallery.php in gadmin/, which allows remote attackers to edit objects via a direct request, different vectors than...Show more
Gallarific Free Edition 1.1 does not require authentication for (1) photos.php, (2) comments.php, and (3) gallery.php in gadmin/, which allows remote attackers to edit objects via a direct request, different vectors than CVE-2008-1327. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Plone
1Plone Cms
Apr 23, 2026
Mar 20, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for context-dependent attackers to reuse a logged-out session.
1Sun
1Solaris
Apr 23, 2026
Mar 17, 2008
N/A· v4
N/A· v3
6.3 MEDIUM· v2
Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local users to bypass authentication via unknown vectors that cause the screen...Show more
Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local users to bypass authentication via unknown vectors that cause the screen saver to crash.Show less
1Bt
1Home Hub
Apr 23, 2026
Mar 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP telephone calls, by placing a character at the end of the PATH_INFO, as...Show more
cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP telephone calls, by placing a character at the end of the PATH_INFO, as demonstrated by (1) %5C (encoded backslash), (2) '%' (percent), and (3) '~' (tilde). NOTE: the '/' (slash) vector is already covered by CVE-2007-5383.Show less
1Gallarific
1Gallarific
Apr 23, 2026
Mar 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct request. NOTE: the provenance of this information is unknown; the details...Show more
Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Asg Sentry
1Asg Sentry
Apr 23, 2026
Mar 13, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of service (service termination) via the exit command to TCP port 6162, or...Show more
The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of service (service termination) via the exit command to TCP port 6162, or have other impacts via other commands.Show less
1Alice
1Gate2 Plus Wi Fi
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
7.1 HIGH· v2
cp06_wifi_m_nocifr.cgi in the admin panel on the Alice Gate 2 Plus Wi-Fi router does not verify authentication credentials, which allows remote attackers to disable Wi-Fi encryption via a certain request.
1Linksys
1Wrt54g
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
The FTP server on the Linksys WRT54G 7 router with 7.00.1 firmware does not verify authentication credentials, which allows remote attackers to establish an FTP session by sending an arbitrary username and password.
1Linksys
1Wrt54g
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
The Linksys WRT54G router has "admin" as its default FTP password, which allows remote attackers to access sensitive files including nvram.cfg, a file that lists all HTML documents, and an ELF executable file.
1Airspan
1Wimax Prost
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malformed firmware or (2) bind the antenna to...Show more
The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malformed firmware or (2) bind the antenna to a different WiMAX base station via unspecified requests to forms under process_adv/.Show less
1Zyxel
1P 2602hw D1a
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a user wh...Show more
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a user who previously authenticated within the previous 5 minutes.Show less
1Belkin
1F5d7230 4
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform administrative actions, as demonstrated by changing a DNS server via th...Show more
cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform administrative actions, as demonstrated by changing a DNS server via the dns1_1, dns1_2, dns1_3, and dns1_4 parameters. NOTE: it was later reported that F5D7632-4V6 with firmware 6.01.08 is also affected.Show less
1Omegasoft
1Interneserviceslosungen
Apr 23, 2026
Mar 4, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attackers to login as an arbitrary user via a modified cookie.
1Ibm
1Websphere Mq
Apr 23, 2026
Mar 4, 2008
N/A· v4
N/A· v3
6.6 MEDIUM· v2
Unspecified vulnerability in IBM WebSphere MQ 6.0.x before 6.0.2.2 and 5.3 before Fix Pack 14 allows attackers to bypass access restrictions for a queue manager via a SVRCONN (MQ client) channel.
1Bea
1Weblogic Server
Apr 23, 2026
Feb 22, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
BEA WebLogic Server and WebLogic Express 6.1 through 10.0 allows remote attackers to bypass authentication for application servlets via crafted request headers.
1Drupal
1Header Image
Apr 23, 2026
Feb 19, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages via unknown attack vectors.
1Symantec
1Ghost Solutions Suite
Apr 23, 2026
Feb 8, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via...Show more
Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing.Show less
1Manageengine
1Applications Manager
Apr 23, 2026
Jan 29, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote attackers to obtain sensitive information and change settings via unspeci...Show more
ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote attackers to obtain sensitive information and change settings via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less