Total
2926 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-6763 | 1 Hypersilence | 1 Silentum Loginsys | 2017-09-28 | 7.5 HIGH | N/A |
login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's username. | |||||
CVE-2008-6939 | 1 Turnkeyforms | 1 Web Hosting Directory | 2017-09-28 | 7.5 HIGH | N/A |
TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie to 1 or (2) gain privileges as another user by setting the logged cookie to the target username. | |||||
CVE-2008-6804 | 1 Tribiq | 1 Tribiq Cms | 2017-09-28 | 7.5 HIGH | N/A |
** DISPUTED ** Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NOTE: a third party reports that the vendor disputes the existence of this issue. | |||||
CVE-2008-6523 | 1 Cale Dunlap | 1 Openinvoice | 2017-09-28 | 7.5 HIGH | N/A |
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE: this can be leveraged with a separate vulnerability in resetpass.php to modify passwords for arbitrary users. | |||||
CVE-2008-6718 | 1 Uochm | 1 Justbookit | 2017-09-28 | 7.5 HIGH | N/A |
U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) user_manual.php, (2) user_config.php, (3) user_kundnamn.php, (4) user_kundlista.php, (5) user_aktiva_kunder.php, (6) database.php, and possibly (7) index.php. | |||||
CVE-2008-6269 | 1 Joovili | 1 Joovili | 2017-09-28 | 7.5 HIGH | N/A |
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username cookies for user privileges; (2) session_admin_id, session_admin_username, and session_admin cookies for admin privileges; and (3) session_staff_id, session_staff_username, and session_staff cookies for staff users. | |||||
CVE-2008-6719 | 1 Uochm | 1 Justlistit | 2017-09-28 | 7.5 HIGH | N/A |
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) start.php, (2) aktivitet.php, (3) prop_aktivitet.php, (4) kategorier.php, (5) konfig.php, (6) security.php, (7) manual.php, and possibly (8) index.php. | |||||
CVE-2008-6951 | 1 Cms.maury91 | 1 Maurycms | 2017-09-28 | 7.5 HIGH | N/A |
MauryCMS 0.53.2 and earlier does not require administrative authentication for Editors/fckeditor/editor/filemanager/browser/default/browser.html, which allows remote attackers to upload arbitrary files via a direct request. | |||||
CVE-2008-6815 | 1 Myktools | 1 Myktools | 2017-09-28 | 5.0 MEDIUM | N/A |
mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a direct request, and then sending an unspecified request to the download page for the backup. | |||||
CVE-2008-6667 | 1 Marc Melvin | 1 A\+ Php Scripts News Management System | 2017-09-28 | 7.5 HIGH | N/A |
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1. | |||||
CVE-2008-6965 | 1 Aj Square | 1 Aj Auction | 2017-09-28 | 7.5 HIGH | N/A |
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a direct request to (1) site.php, (2) auction.php, (3) mail.php, (4) fee_setting.php, (5) earnings.php, (6) insertion_fee_settings.php, (7) custom_category.php, (8) subcategory.php, (9) category.php, (10) report.php, (11) store_manager.php, and (12) choose_sell_format.php in admin/, and possibly other vectors. | |||||
CVE-2009-0642 | 1 Ruby-lang | 1 Ruby | 2017-09-28 | 6.8 MEDIUM | N/A |
ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate. | |||||
CVE-2008-5125 | 1 Castillocentral | 1 Ccleague | 2017-09-28 | 6.8 MEDIUM | N/A |
admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin. | |||||
CVE-2008-5880 | 1 Gobbl | 1 Gobbl Cms | 2017-09-28 | 7.5 HIGH | N/A |
admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok". | |||||
CVE-2008-5784 | 1 V3chat | 1 V3 Chat Profiles Dating Script | 2017-09-28 | 7.5 HIGH | N/A |
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1. | |||||
CVE-2008-5783 | 1 V3chat | 1 V3 Chat Live Support | 2017-09-28 | 7.5 HIGH | N/A |
admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1. | |||||
CVE-2008-5708 | 1 Slimcms | 1 Slimcms | 2017-09-28 | 7.5 HIGH | N/A |
redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1. | |||||
CVE-2008-5576 | 1 Scssboard | 1 Scssboard | 2017-09-28 | 7.5 HIGH | N/A |
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter. | |||||
CVE-2008-5497 | 1 Bandsitecms | 1 Bandsite Cms | 2017-09-28 | 7.5 HIGH | N/A |
BandSite CMS 1.1.4 allows remote attackers to bypass authentication and gain administrative access by setting the login_auth cookie to true. | |||||
CVE-2008-5355 | 1 Sun | 3 Jdk, Jre, Sdk | 2017-09-28 | 10.0 HIGH | N/A |
The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks. |