Vulnerabilities (CVE)

Filtered by CWE-287
Total 3371 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6455 1 Edikon 1 Phpshop 2024-11-21 6.8 MEDIUM N/A
Session fixation vulnerability in Edikon phpShop 0.8.1 allows remote attackers to hijack web sessions via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6445 1 Yourplace 1 Yourplace 2024-11-21 7.5 HIGH N/A
Unspecified vulnerability in YourPlace before 1.0.1 has unknown impact and attack vectors, possibly related to improper authentication and the ability to upload arbitrary PHP code. NOTE: some of these details are obtained from third party information.
CVE-2008-6440 2 Cerberus, Webgroupmedia 2 Cerberus Helpdesk, Cerberus Helpdesk 2024-11-21 5.0 MEDIUM N/A
Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs.
CVE-2008-6411 1 Explay 1 Explay Cms 2024-11-21 7.5 HIGH N/A
Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1.
CVE-2008-6307 1 E-topbiz 1 Link Back Checker 2024-11-21 7.5 HIGH N/A
E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin."
CVE-2008-6300 1 Gwm 1 Galatolo Webmanager 2024-11-21 7.5 HIGH N/A
Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6269 1 Joovili 1 Joovili 2024-11-21 7.5 HIGH N/A
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username cookies for user privileges; (2) session_admin_id, session_admin_username, and session_admin cookies for admin privileges; and (3) session_staff_id, session_staff_username, and session_staff cookies for staff users.
CVE-2008-6162 1 Bux 1 Bux.to Clone Script 2024-11-21 7.5 HIGH N/A
Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNick cookie to admin.
CVE-2008-6143 1 Owentechkenya 1 Owenpoll 2024-11-21 7.5 HIGH N/A
OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie.
CVE-2008-6131 1 Mozilo 1 Mozilowiki 2024-11-21 6.0 MEDIUM N/A
Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
CVE-2008-6128 1 Mozilo 1 Mozilocms 2024-11-21 6.8 MEDIUM N/A
Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
CVE-2008-6118 1 Goople Cms 1 Goople Cms 2024-11-21 7.5 HIGH N/A
win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1.
CVE-2008-6092 1 Phpscripts 1 Ranking-script 2024-11-21 7.5 HIGH N/A
phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie.
CVE-2008-6045 1 Xt-commerce 1 Xt-commerce 2024-11-21 6.8 MEDIUM N/A
Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter.
CVE-2008-6039 1 Bluepage 1 Bluepage Cms 2024-11-21 6.8 MEDIUM N/A
Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
CVE-2008-6009 1 Sg Real Estate Portal 1 Sg Real Estate Portal 2024-11-21 7.5 HIGH N/A
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.
CVE-2008-5967 1 Phpicalendar 1 Phpicalendar 2024-11-21 7.5 HIGH N/A
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.
CVE-2008-5964 1 Impresscms 1 Impresscms 2024-11-21 6.8 MEDIUM N/A
Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
CVE-2008-5945 1 Nukevietcms 1 Nukeviet 2024-11-21 7.5 HIGH N/A
Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-5880 1 Gobbl 1 Gobbl Cms 2024-11-21 7.5 HIGH N/A
admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok".