Total
3371 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-4927 | 1 Webmobo | 1 Wbnews | 2024-11-21 | 7.5 HIGH | N/A |
WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated by setting this cookie to 1. | |||||
CVE-2009-4909 | 1 Dootzky | 1 Oblog | 2024-11-21 | 6.8 MEDIUM | N/A |
admin/index.php in oBlog allows remote attackers to conduct brute-force password guessing attacks via HTTP requests. | |||||
CVE-2009-4879 | 1 Novell | 1 Access Manager | 2024-11-21 | 4.3 MEDIUM | N/A |
The Identity Server in Novell Access Manager before 3.1 SP1 allows attackers with disabled Active Directory accounts to authenticate using X.509 authentication, which bypasses intended access restrictions. | |||||
CVE-2009-4843 | 1 Toutvirtual | 1 Virtualiq | 2024-11-21 | 7.5 HIGH | N/A |
ToutVirtual VirtualIQ Pro before 3.5 build 8691 does not require administrative authentication for JBoss console access, which allows remote attackers to execute arbitrary commands via requests to (1) the JMX Management Console or (2) the Web Console. | |||||
CVE-2009-4830 | 1 Openx | 1 Openx | 2024-11-21 | 7.5 HIGH | N/A |
Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator account via unknown vectors, possibly related to www/admin/install.php, www/admin/install-plugins.php, and other www/admin/ files. | |||||
CVE-2009-4821 | 1 Dlink | 1 Dir-615 | 2024-11-21 | 5.0 MEDIUM | N/A |
The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1) change the admin password via the admin_password parameter, (2) disable the security requirement for the Wi-Fi network via unspecified vectors, or (3) modify DNS settings via unspecified vectors. | |||||
CVE-2009-4808 | 1 Graugon | 1 Php Article Publisher | 2024-11-21 | 7.5 HIGH | N/A |
admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_admin cookie to 1. | |||||
CVE-2009-4806 | 1 Digitalinterchange | 1 Digital Interchange Document Library | 2024-11-21 | 7.5 HIGH | N/A |
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator's credentials via unspecified vectors. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-4801 | 1 Will Kraft | 1 Ez-blog | 2024-11-21 | 7.5 HIGH | N/A |
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts. | |||||
CVE-2009-4675 | 1 Mole-group | 1 Gastro Portal \(restaurant Directory\) Script | 2024-11-21 | 7.5 HIGH | N/A |
admin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative authentication, which allows remote attackers to change the admin password via an unspecified form submission. | |||||
CVE-2009-4671 | 1 Beaussier | 1 Roomphplanning | 2024-11-21 | 7.5 HIGH | N/A |
Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by setting the room_phplanning cookie to a value associated with the admin account. | |||||
CVE-2009-4670 | 1 Beaussier | 1 Roomphplanning | 2024-11-21 | 7.5 HIGH | N/A |
admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary rooms via the room parameter. | |||||
CVE-2009-4657 | 1 Omidrouhani | 1 Xerver | 2024-11-21 | 7.5 HIGH | N/A |
The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardStep1. | |||||
CVE-2009-4584 | 1 Dbmasters | 1 Db Masters Multimedia Links Directory | 2024-11-21 | 7.5 HIGH | N/A |
admin.php in dB Masters Multimedia Links Directory 3.1.3 allows remote attackers to bypass authentication and gain administrative access via a certain value of the admin_log cookie. | |||||
CVE-2009-4447 | 1 Jax Scripts | 1 Jax Guestbook | 2024-11-21 | 7.5 HIGH | N/A |
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.php. | |||||
CVE-2009-4409 | 1 Iij | 1 Seil\/b1 | 2024-11-21 | 2.6 LOW | N/A |
The (1) CHAP and (2) MS-CHAP-V2 authentication capabilities in the PPP Access Concentrator (PPPAC) function in Internet Initiative Japan SEIL/B1 firmware 1.00 through 2.52 use the same challenge for each authentication attempt, which allows remote attackers to bypass authentication via a replay attack. | |||||
CVE-2009-4367 | 1 Sitecore | 1 Staging Module | 2024-11-21 | 6.8 MEDIUM | N/A |
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3) list directories, and (4) clear the server cache via crafted SOAP requests with arbitrary Username and Password values, possibly related to a direct request. | |||||
CVE-2009-4232 | 2 Jonijnm, Joomla | 2 Com Kide, Joomla\! | 2024-11-21 | 5.0 MEDIUM | N/A |
The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an insertar action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2009-4151 | 1 Bestpractical | 1 Rt | 2024-11-21 | 5.8 MEDIUM | N/A |
Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows remote attackers to hijack web sessions by setting the session identifier via a manipulation that leverages "HTTP access to the RT server," a related issue to CVE-2009-3585. | |||||
CVE-2009-4128 | 1 Gnu | 1 Grub 2 | 2024-11-21 | 7.2 HIGH | N/A |
GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for physically proximate attackers to conduct brute force attacks and bypass authentication by submitting a password whose length is 1. |