CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,585 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 2 of 92
- CVE-2006-6997HIGHCVSS v2 10.0EG 10.02007-02-12
Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edition before 1.21 leads to "weakened authentication security" with unknown impact and attac…
- CVE-2007-0435HIGHCVSS v2 7.5EG 7.52007-01-23
T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the device via a LOGINKEY=TECOM cookie value.
- CVE-2007-1062HIGHCVSS v2 10.0EG 10.02007-02-22
The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL r…
- CVE-2007-1160HIGHCVSS v2 10.0EG 10.02007-03-02
webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782.
- CVE-2007-1228MEDIUMCVSS v2 4.4EG 4.42007-03-02
IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.
- CVE-2007-1480HIGHCVSS v2 7.5EG 7.52007-03-16
Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set.
- CVE-2007-1859MEDIUMCVSS v2 4.6EG 4.62007-05-02
XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unloc…
- CVE-2007-1949HIGHCVSS v2 7.5EG 7.52007-04-11
Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
- CVE-2007-1951HIGHCVSS v2 7.5EG 7.52007-04-11
Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
- CVE-2007-1952HIGHCVSS v2 7.5EG 7.52007-04-11
Session fixation vulnerability in onelook onebyone CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
- CVE-2007-1953HIGHCVSS v2 7.5EG 7.52007-04-11
Session fixation vulnerability in onelook courts on-line allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
- CVE-2007-1966CRITICALCVSS 9.1EG 9.12007-04-11
Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.
- CVE-2007-2243MEDIUMCVSS v2 5.0EG 5.02007-04-25
OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account …
- CVE-2007-2277HIGHCVSS v2 7.5EG 7.52007-04-25
Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
- CVE-2007-2546MEDIUMCVSS v2 6.8EG 6.82007-05-09
Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
- CVE-2007-2555MEDIUMCVSS v2 4.3EG 4.32007-05-09
Unspecified vulnerability in Default.aspx in Podium CMS allows remote attackers to have an unknown impact, possibly session fixation, via a META HTTP-EQUIV Set-cookie expression in the id parameter, related to "cookie manipulation." NOTE:…
- CVE-2007-2719HIGHCVSS v2 10.0EG 10.02007-05-16
Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting the JSESSIONID cookie.
- CVE-2007-3050HIGHCVSS v2 7.5EG 7.52007-06-06
Session fixation vulnerability in chameleon cms 3.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
- CVE-2007-3177MEDIUMCVSS v2 5.0EG 5.02007-06-11
Ingate Firewall and SIParator before 4.5.2 allow remote attackers to bypass SIP authentication via a certain maddr parameter.
- CVE-2007-3184HIGHCVSS v2 7.2EG 7.22007-06-12
Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server…
- CVE-2007-3597HIGHCVSS v2 8.5EG 8.52007-07-06
Session fixation vulnerability in Zen Cart 1.3.7 and earlier allows remote attackers to hijack web sessions by setting the Cookie parameter.
- CVE-2007-3754MEDIUMCVSS v2 4.3EG 4.32007-09-27
Mail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers to steal credentials and read email via a man-in-the-middle (MITM) attack.
- CVE-2007-3988MEDIUMCVSS v2 6.8EG 6.82007-07-25
Session fixation vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
- CVE-2007-4203HIGHCVSS v2 9.3EG 9.32007-08-08
Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.
- CVE-2007-4364HIGHCVSS v2 8.5EG 8.52007-08-15
Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to (1) a nonexistent account name in combination with an empty password, which allows remote…
- CVE-2007-4419HIGHCVSS v2 9.3EG 9.32007-08-18
Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin a…
- CVE-2007-4438MEDIUMCVSS v2 6.8EG 6.82007-08-20
Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.
- CVE-2007-4548HIGHCVSS v2 10.0EG 10.02007-08-27
The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administr…
- CVE-2007-4632MEDIUMCVSS v2 4.3EG 4.32007-08-31
Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to byp…
- CVE-2007-4680MEDIUMCVSS v2 6.8EG 6.82007-11-15
CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted SSL certificates via a man-in-the-middle attack.
- CVE-2007-4692MEDIUMCVSS v2 4.3EG 4.32007-11-15
The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an …
- CVE-2007-4693HIGHCVSS v2 7.2EG 7.22007-11-15
The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen saver and send keystrokes to a process, related to "handling of keyboard focus between sec…
- CVE-2007-4747HIGHCVSS v2 10.0EG 10.02007-09-06
The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmwar…
- CVE-2007-5006HIGHCVSS v2 10.0EG 10.02007-10-01
Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete users, and start client…
- CVE-2007-5008HIGHCVSS v2 9.0EG 9.02007-09-20
The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.
- CVE-2007-5057HIGHCVSS v2 10.0EG 10.02007-09-24
NetSupport Manager Client before 10.20.0004 allows remote attackers to bypass the (1) basic and (2) authentication schemes by spoofing the NetSupport Manager.
- CVE-2007-5085MEDIUMCVSS v2 5.0EG 5.02007-09-26
Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
- CVE-2007-5113MEDIUMCVSS v2 5.0EG 5.02007-09-26
report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and g…
- CVE-2007-5152HIGHCVSS v2 7.5EG 7.52007-10-01
Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks.
- CVE-2007-5162MEDIUMCVSS v2 4.3EG 4.32007-10-01
The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS request, which makes…
- CVE-2007-5374MEDIUMCVSS v2 6.5EG 6.52007-10-11
cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticated users to increase the privileges of any account.
- CVE-2007-5383HIGHCVSS v2 10.0EG 10.02007-10-12
The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative access via vectors including a '/' (slash) character at the …
- CVE-2007-5391HIGHCVSS v2 10.0EG 10.02007-10-12
Unspecified vulnerability in HP Select Identity 4.01 through 4.01.010 and 4.10 through 4.13.001 allows remote attackers to obtain unspecified access via unknown vectors.
- CVE-2007-5578HIGHCVSS v2 7.5EG 7.52007-10-18
Basic Analysis and Security Engine (BASE) before 1.3.8 sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication via (1) base_main.php, (2) base_qry_alert.php, and possibly other vectors.
- CVE-2007-5714MEDIUMCVSS v2 6.8EG 6.82007-10-30
The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.
- CVE-2007-5752HIGHCVSS v2 7.5EG 7.52007-10-31
adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via a modified form, as demonstrated by an account with admin (userlevel 4) privileges.
- CVE-2007-5770MEDIUMCVSS v2 5.0EG 5.02007-11-14
The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the commonName (CN) field in a server certificate matches the domain name in a request sent over SSL…
- CVE-2007-5791HIGHCVSS v2 10.0EG 10.02007-11-01
The Vonage Motorola Phone Adapter VT 2142-VD does not properly verify that a SIP INVITE message originated from a legitimate server, which allows remote attackers to send spoofed INVITE messages, as demonstrated by a flood of messages trig…
- CVE-2007-5797HIGHCVSS v2 7.5EG 7.52007-11-03
SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
- CVE-2007-5855MEDIUMCVSS v2 6.4EG 6.42007-12-19
Mail in Apple Mac OS X 10.4.11 and 10.5.1, when an SMTP account has been set up using Account Assistant, can use plaintext authentication even when MD5 Challenge-Response authentication is available, which makes it easier for remote attack…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →