← Back
CWE-287

4,777 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,777)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Simple Machines
1Simple Machines Forum
Apr 23, 2026
May 9, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
1Xscreensaver
1Xscreensaver
Apr 23, 2026
May 2, 2007
N/A· v4
N/A· v3
4.6 MEDIUM· v2
XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver...Show more
XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.Show less
1Plogger
1Plogger
Apr 23, 2026
Apr 25, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
1Openbsd
1Openssh
Apr 23, 2026
Apr 25, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response i...Show more
OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.Show less
1Exv2
1Content Management System
Apr 23, 2026
Apr 11, 2007
N/A· v4
9.1 CRITICAL· v3
5.0 MEDIUM· v2
Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.
1Onelook
1Courts Online
Apr 23, 2026
Apr 11, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Session fixation vulnerability in onelook courts on-line allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
1Onelook
1Onebyone Cms
Apr 23, 2026
Apr 11, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Session fixation vulnerability in onelook onebyone CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
1Onelook
1Oboshop
Apr 23, 2026
Apr 11, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
1Webblizzard
1Content Management System
Apr 23, 2026
Apr 11, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
1Creative Guestbook
1Creative Guestbook
Apr 23, 2026
Mar 16, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set.
1Ibm
1Db2
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
4.4 MEDIUM· v2
IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.
1Webspell
1Webspell
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782.
1Cisco
2Unified Ip Conference Station 7935 Firmware
Unified Ip Conference Station Firmware 7936
Apr 23, 2026
Feb 22, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls...Show more
The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited timeShow less
1Mailenable
2Mailenable Enterprise
Mailenable Standard
Apr 23, 2026
Feb 12, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edition before 1.21 leads to "weakened authentication security" with unkno...Show more
Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edition before 1.21 leads to "weakened authentication security" with unknown impact and attack vectors. NOTE: due to lack of details, it is not clear whether this is the same as CVE-2006-1792.Show less
1T Com
2Speedport 500v
Speedport 500v Firmware
Apr 23, 2026
Jan 23, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the device via a LOGINKEY=TECOM cookie value.
1Logahead
1Logahead Unu
Apr 23, 2026
Dec 28, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
logahead UNU 1.0 before 20061226 allows remote attackers to upload arbitrary files via unspecified vectors related to plugins/widged/_widged.php (aka the WidgEd plugin), possibly because of an authentication bypass. NOTE...Show more
logahead UNU 1.0 before 20061226 allows remote attackers to upload arbitrary files via unspecified vectors related to plugins/widged/_widged.php (aka the WidgEd plugin), possibly because of an authentication bypass. NOTE: some of these details are obtained from third party information.Show less
1Soumu
3Koukyoumuke Soumu Workflow
Soumo WorkflowSoumu Workflow
Apr 23, 2026
Dec 23, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple unspecified vulnerabilities in the template files in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01-00 through 01-01 allow remote attackers...Show more
Multiple unspecified vulnerabilities in the template files in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01-00 through 01-01 allow remote attackers to bypass authentication mechanisms on web pages via unknown vectors.Show less
1Sql Ledger
1Sql Ledger
Apr 16, 2026
Aug 31, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged...Show more
SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value.Show less
2Dell
Fuji Xerox
193000cn
3010cn3100cn+16 more
Apr 16, 2026
Aug 25, 2006
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firm...Show more
The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, does not properly perform authentication for HTTP requests, which allows remote attackers to modify system configuration via crafted requests, including changing the administrator password or causing a denial of service to the print server.Show less
1Jetbox
1Jetbox Cms
Apr 16, 2026
Aug 8, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator section.