Total
3371 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-6455 | 1 Edikon | 1 Phpshop | 2024-11-21 | 6.8 MEDIUM | N/A |
Session fixation vulnerability in Edikon phpShop 0.8.1 allows remote attackers to hijack web sessions via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-6445 | 1 Yourplace | 1 Yourplace | 2024-11-21 | 7.5 HIGH | N/A |
Unspecified vulnerability in YourPlace before 1.0.1 has unknown impact and attack vectors, possibly related to improper authentication and the ability to upload arbitrary PHP code. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-6440 | 2 Cerberus, Webgroupmedia | 2 Cerberus Helpdesk, Cerberus Helpdesk | 2024-11-21 | 5.0 MEDIUM | N/A |
Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs. | |||||
CVE-2008-6411 | 1 Explay | 1 Explay Cms | 2024-11-21 | 7.5 HIGH | N/A |
Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1. | |||||
CVE-2008-6307 | 1 E-topbiz | 1 Link Back Checker | 2024-11-21 | 7.5 HIGH | N/A |
E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin." | |||||
CVE-2008-6300 | 1 Gwm | 1 Galatolo Webmanager | 2024-11-21 | 7.5 HIGH | N/A |
Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-6269 | 1 Joovili | 1 Joovili | 2024-11-21 | 7.5 HIGH | N/A |
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username cookies for user privileges; (2) session_admin_id, session_admin_username, and session_admin cookies for admin privileges; and (3) session_staff_id, session_staff_username, and session_staff cookies for staff users. | |||||
CVE-2008-6162 | 1 Bux | 1 Bux.to Clone Script | 2024-11-21 | 7.5 HIGH | N/A |
Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNick cookie to admin. | |||||
CVE-2008-6143 | 1 Owentechkenya | 1 Owenpoll | 2024-11-21 | 7.5 HIGH | N/A |
OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie. | |||||
CVE-2008-6131 | 1 Mozilo | 1 Mozilowiki | 2024-11-21 | 6.0 MEDIUM | N/A |
Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | |||||
CVE-2008-6128 | 1 Mozilo | 1 Mozilocms | 2024-11-21 | 6.8 MEDIUM | N/A |
Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | |||||
CVE-2008-6118 | 1 Goople Cms | 1 Goople Cms | 2024-11-21 | 7.5 HIGH | N/A |
win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1. | |||||
CVE-2008-6092 | 1 Phpscripts | 1 Ranking-script | 2024-11-21 | 7.5 HIGH | N/A |
phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie. | |||||
CVE-2008-6045 | 1 Xt-commerce | 1 Xt-commerce | 2024-11-21 | 6.8 MEDIUM | N/A |
Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter. | |||||
CVE-2008-6039 | 1 Bluepage | 1 Bluepage Cms | 2024-11-21 | 6.8 MEDIUM | N/A |
Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | |||||
CVE-2008-6009 | 1 Sg Real Estate Portal | 1 Sg Real Estate Portal | 2024-11-21 | 7.5 HIGH | N/A |
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1. | |||||
CVE-2008-5967 | 1 Phpicalendar | 1 Phpicalendar | 2024-11-21 | 7.5 HIGH | N/A |
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root. | |||||
CVE-2008-5964 | 1 Impresscms | 1 Impresscms | 2024-11-21 | 6.8 MEDIUM | N/A |
Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | |||||
CVE-2008-5945 | 1 Nukevietcms | 1 Nukeviet | 2024-11-21 | 7.5 HIGH | N/A |
Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-5880 | 1 Gobbl | 1 Gobbl Cms | 2024-11-21 | 7.5 HIGH | N/A |
admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok". |