CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,924 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 10 of 99
- CVE-2009-4089MEDIUMCVSS v2 5.0EG 5.02009-11-29
telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a modified pageID parameter to ajax/deletePage.php or (2) delete arbitrary comments via a modified pageID parameter to ajax…
- CVE-2009-4095HIGHCVSS v2 7.5EG 7.52009-11-29
myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party information.
- CVE-2009-4128HIGHCVSS v2 7.2EG 7.22009-12-01
GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for physically proximate attackers to conduct brute force attacks and bypass authentication by sub…
- CVE-2009-4151MEDIUMCVSS v2 5.8EG 5.82009-12-02
Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows remote attackers to hijack web sessions by setting the session identifier via a manipulati…
- CVE-2009-4232MEDIUMCVSS v2 5.0EG 5.02009-12-08
The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an insertar action to index.php. NOTE: the provenance of …
- CVE-2009-4367MEDIUMCVSS v2 6.8EG 6.82009-12-21
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3) list directories, a…
- CVE-2009-4409LOWCVSS v2 2.6EG 2.62009-12-23
The (1) CHAP and (2) MS-CHAP-V2 authentication capabilities in the PPP Access Concentrator (PPPAC) function in Internet Initiative Japan SEIL/B1 firmware 1.00 through 2.52 use the same challenge for each authentication attempt, which allow…
- CVE-2009-4447HIGHCVSS v2 7.5EG 7.52009-12-29
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.php.
- CVE-2009-4584HIGHCVSS v2 7.5EG 7.52010-01-06
admin.php in dB Masters Multimedia Links Directory 3.1.3 allows remote attackers to bypass authentication and gain administrative access via a certain value of the admin_log cookie.
- CVE-2009-4657HIGHCVSS v2 7.5EG 7.52010-03-03
The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardSt…
- CVE-2009-4670HIGHCVSS v2 7.5EG 7.52010-03-05
admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary rooms via the room parameter.
- CVE-2009-4671HIGHCVSS v2 7.5EG 7.52010-03-05
Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by setting the room_phplanning cookie to a value associated with the admin account.
- CVE-2009-4675HIGHCVSS v2 7.5EG 7.52010-03-05
admin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative authentication, which allows remote attackers to change the admin password via an unspecified form submission.
- CVE-2009-4801HIGHCVSS v2 7.5EG 7.52010-04-23
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts.
- CVE-2009-4806HIGHCVSS v2 7.5EG 7.52010-04-23
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator's credentials via unspecified vectors. NOTE: some of these…
- CVE-2009-4808HIGHCVSS v2 7.5EG 7.52010-04-23
admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_admin cookie to 1.
- CVE-2009-4821MEDIUMCVSS v2 5.0EG 5.02010-04-27
The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1) change the admin password via the admin_password parameter, (2) disable the security requirement for…
- CVE-2009-4830HIGHCVSS v2 7.5EG 7.52010-04-27
Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator account via unknown vectors, possibly related to www/admin/install.php, www/admin/install-plugins.php…
- CVE-2009-4843HIGHCVSS v2 7.5EG 7.52010-05-07
ToutVirtual VirtualIQ Pro before 3.5 build 8691 does not require administrative authentication for JBoss console access, which allows remote attackers to execute arbitrary commands via requests to (1) the JMX Management Console or (2) the …
- CVE-2009-4879MEDIUMCVSS v2 4.3EG 4.32010-05-26
The Identity Server in Novell Access Manager before 3.1 SP1 allows attackers with disabled Active Directory accounts to authenticate using X.509 authentication, which bypasses intended access restrictions.
- CVE-2009-4909MEDIUMCVSS v2 6.8EG 6.82010-06-25
admin/index.php in oBlog allows remote attackers to conduct brute-force password guessing attacks via HTTP requests.
- CVE-2009-4927HIGHCVSS v2 7.5EG 7.52010-07-12
WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated by setting this cookie to 1.
- CVE-2009-4929HIGHCVSS v2 7.5EG 7.52010-07-12
admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the newPW1 and newPW2 parameters.
- CVE-2009-4987HIGHCVSS v2 7.5EG 7.52010-08-25
admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting the cookgid cookie value to 1, a different vector than CVE-2008-3211.
- CVE-2009-5076HIGHCVSS v2 7.5EG 7.52011-06-08
CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator privileges via a request with (1) login.php or (2) password_forgotten.php appended as the PATH_INFO…
- CVE-2009-5077HIGHCVSS v2 7.5EG 7.52011-06-08
CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) includes/application_top.php and (2) admi…
- CVE-2009-5083MEDIUMCVSS v2 6.8EG 6.82011-08-12
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not perform the expected login rejection upon receiving an OP-Identifier from an OpenID provider, which allows remote attac…
- CVE-2009-5116MEDIUMCVSS v2 6.5EG 6.52012-08-22
McAfee LinuxShield 1.5.1 and earlier does not properly implement client authentication, which allows remote authenticated users to obtain Admin access to the statistics server by leveraging a client account.
- CVE-2010-0014LOWCVSS v2 3.7EG 3.72010-01-14
System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary password, to the screen-locking program on a…
- CVE-2010-0447HIGHCVSS v2 10.0EG 10.02010-03-10
The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via vectors involving upl…
- CVE-2010-0498HIGHCVSS v2 7.2EG 7.22010-03-30
Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local users to gain privileges via unspecified vectors.
- CVE-2010-0521MEDIUMCVSS v2 5.0EG 5.02010-03-30
Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to obtain potentially sensitive information from Open Directory via unspecified LDAP requests.
- CVE-2010-0550MEDIUMCVSS v2 4.0EG 4.02010-02-04
admin.htm in Geo++ GNCASTER 1.4.0.7 and earlier does not properly enforce HTTP Digest Authentication, which allows remote authenticated users to use HTTP Basic Authentication, bypassing intended server policy.
- CVE-2010-0554HIGHCVSS v2 7.5EG 7.52010-02-04
The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attackers to hijack web sessions or bypass authentication via a replay attack.
- CVE-2010-0744MEDIUMCVSS v2 5.8EG 5.82010-04-20
aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which …
- CVE-2010-0756MEDIUMCVSS v2 5.8EG 5.82010-02-27
Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.php/Comment/Main, (2) index.php/Comment/Main/Home_Wiky, or (3) index.php/Edit/Main.
- CVE-2010-0833HIGHCVSS v2 9.3EG 9.32010-07-28
The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a …
- CVE-2010-0834HIGHCVSS v2 9.3EG 9.32010-08-10
The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote arch…
- CVE-2010-1040MEDIUMCVSS v2 5.8EG 5.82010-03-23
The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device support is enabled, allows remote attackers to bypass the "simple login" functionality via u…
- CVE-2010-1097MEDIUMCVSS v2 6.8EG 6.82010-03-24
include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated…
- CVE-2010-1191MEDIUMCVSS v2 6.4EG 6.42010-03-31
Sahana disaster management system 0.6.2.2, and possibly other versions, allows remote attackers to bypass intended access restrictions and disable administrator authentication via a direct request to stream.php in an acl_enable_acl action …
- CVE-2010-1221MEDIUMCVSS v2 5.0EG 5.02010-04-07
CA XOsoft r12.0 and r12.5 does not properly perform authentication, which allows remote attackers to enumerate usernames via a SOAP request.
- CVE-2010-1222MEDIUMCVSS v2 5.0EG 5.02010-04-07
CA XOsoft r12.5 does not properly perform authentication, which allows remote attackers to obtain potentially sensitive information via a SOAP request.
- CVE-2010-1375HIGHCVSS v2 7.2EG 7.22010-06-17
NetAuthSysAgent in Network Authorization in Apple Mac OS X 10.5.8 does not have the expected authorization requirements, which allows local users to gain privileges via unspecified vectors.
- CVE-2010-1454MEDIUMCVSS v2 6.8EG 6.82010-05-19
com.springsource.tcserver.serviceability.rmi.JmxSocketListener in VMware SpringSource tc Server Runtime 6.0.19 and 6.0.20 before 6.0.20.D, and 6.0.25.A before 6.0.25.A-SR01, does not properly enforce the requirement for an encrypted (aka s…
- CVE-2010-1596MEDIUMCVSS v2 6.8EG 6.82010-04-28
Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
- CVE-2010-1670HIGHCVSS v2 7.5EG 7.52010-07-06
Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 has improper configuration options for authentication plugins associated with logins that use the single sign-on (SSO) functionality, which allows remote attackers to bypass …
- CVE-2010-1802MEDIUMCVSS v2 6.4EG 6.42010-08-25
libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associated with a similar d…
- CVE-2010-1820MEDIUMCVSS v2 6.8EG 6.82010-09-21
Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle errors, which allows remote attackers to bypass the password requirement for shared-folder access by leveraging knowledge of a valid accoun…
- CVE-2010-1838MEDIUMCVSS v2 4.4EG 4.42010-11-15
Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle errors associated with disabled mobile accounts, which allows remote attackers to bypass authentication by providing a valid account name.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →