Total
2926 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-7649 | 1 Eclipse | 1 Kura | 2017-09-29 | 10.0 HIGH | 9.8 CRITICAL |
The network enabled distribution of Kura before 2.1.0 takes control over the device's firewall setup but does not allow IPv6 firewall rules to be configured. Still the Equinox console port 5002 is left open, allowing to log into Kura without any user credentials over unencrypted telnet and executing commands using the Equinox "exec" command. As the process is running as "root" full control over the device can be acquired. IPv6 is also left in auto-configuration mode, accepting router advertisements automatically and assigns a MAC address based IPv6 address. | |||||
CVE-2014-9618 | 1 Netsweeper | 1 Netsweeper | 2017-09-29 | 7.5 HIGH | 9.8 CRITICAL |
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via a showdeny action to the default URL. | |||||
CVE-2009-1587 | 1 Kalptarudemos | 1 Php Site Lock | 2017-09-28 | 7.5 HIGH | N/A |
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, login_name, user_id, and user_type cookies to certain values. | |||||
CVE-2009-1580 | 1 Squirrelmail | 1 Squirrelmail | 2017-09-28 | 5.8 MEDIUM | N/A |
Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie. | |||||
CVE-2009-2117 | 1 Phportal | 1 Phportal | 2017-09-28 | 7.5 HIGH | N/A |
uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username. | |||||
CVE-2009-2168 | 1 Egyplus | 1 7ammel | 2017-09-28 | 7.5 HIGH | N/A |
cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are incorrect, which allows remote attackers to bypass authentication by providing arbitrary username and password parameters. | |||||
CVE-2009-0864 | 1 Matteoiammarrone | 1 S-cms | 2017-09-28 | 7.5 HIGH | N/A |
S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie. | |||||
CVE-2009-2040 | 1 Grestul | 1 Grestul | 2017-09-28 | 7.5 HIGH | N/A |
admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative accounts via a manage_admin action in a direct request. | |||||
CVE-2009-2003 | 1 Ascadnetworks | 1 Password Protector Sd | 2017-09-28 | 7.5 HIGH | N/A |
Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7portal and (2) cookname cookies to "admin." | |||||
CVE-2009-1854 | 1 Cmsnx | 1 Million Dollar Text Links | 2017-09-28 | 7.5 HIGH | N/A |
Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1. | |||||
CVE-2009-1050 | 1 Kamads | 1 Bloginator | 2017-09-28 | 7.5 HIGH | N/A |
Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYourself cookie. | |||||
CVE-2009-1826 | 1 Collector | 1 Mygesuad | 2017-09-28 | 6.5 MEDIUM | N/A |
modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action. | |||||
CVE-2009-1825 | 1 Collector | 1 Mycolex | 2017-09-28 | 4.0 MEDIUM | N/A |
modules/admuser.php in myColex 1.4.2 does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action. | |||||
CVE-2009-1670 | 1 Tcpdb | 1 Tcpdb | 2017-09-28 | 7.5 HIGH | N/A |
user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vectors. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-1489 | 1 Rens Rikkerink | 1 Fungamez | 2017-09-28 | 7.5 HIGH | N/A |
includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie parameter. | |||||
CVE-2009-1504 | 1 Xigla | 1 Absolute Control Panel Xe | 2017-09-28 | 7.5 HIGH | N/A |
Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "lvl=1&userid=1." | |||||
CVE-2009-1664 | 1 Easy-scripts | 1 Answer And Question Script | 2017-09-28 | 7.5 HIGH | N/A |
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via modified userid, txtpassword, and txtRpassword parameters. | |||||
CVE-2009-1638 | 1 T-dreams | 1 Job Career Package | 2017-09-28 | 7.5 HIGH | N/A |
Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin cookie to Login. | |||||
CVE-2009-1619 | 1 Teraway | 1 Filestream | 2017-09-28 | 7.5 HIGH | N/A |
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1. | |||||
CVE-2009-1618 | 1 Teraway | 1 Livehelp | 2017-09-28 | 7.5 HIGH | N/A |
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie. |