CWE-287
4,777 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,777)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Simple Machines 1Simple Machines Forum Apr 23, 2026 May 9, 2007 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. |
XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver...Show more |
Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. |
OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response i...Show more |
1Exv2 1Content Management System Apr 23, 2026 Apr 11, 2007 N/A· v4 9.1 CRITICAL· v3 5.0 MEDIUM· v2 Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie. |
Session fixation vulnerability in onelook courts on-line allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. |
Session fixation vulnerability in onelook onebyone CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. |
Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. |
1Webblizzard 1Content Management System Apr 23, 2026 Apr 11, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. |
1Creative Guestbook 1Creative Guestbook Apr 23, 2026 Mar 16, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set. |
IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories. |
webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782. |
1Cisco 2Unified Ip Conference Station 7935 Firmware Unified Ip Conference Station Firmware 7936Apr 23, 2026 Feb 22, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls...Show more |
1Mailenable 2Mailenable Enterprise Mailenable StandardApr 23, 2026 Feb 12, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edition before 1.21 leads to "weakened authentication security" with unkno...Show more |
1T Com 2Speedport 500v Speedport 500v FirmwareApr 23, 2026 Jan 23, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the device via a LOGINKEY=TECOM cookie value. |
logahead UNU 1.0 before 20061226 allows remote attackers to upload arbitrary files via unspecified vectors related to plugins/widged/_widged.php (aka the WidgEd plugin), possibly because of an authentication bypass. NOTE...Show more |
1Soumu 3Koukyoumuke Soumu Workflow Soumo WorkflowSoumu WorkflowApr 23, 2026 Dec 23, 2006 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple unspecified vulnerabilities in the template files in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01-00 through 01-01 allow remote attackers...Show more |
SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged...Show more |
2Dell Fuji Xerox193000cn 3010cn3100cn+16 moreApr 16, 2026 Aug 25, 2006 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firm...Show more |
Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator section. |