Total
3293 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-6092 | 1 Phpscripts | 1 Ranking-script | 2017-09-29 | 7.5 HIGH | N/A |
phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie. | |||||
CVE-2008-4167 | 1 Ezphotogallery | 1 Ezphotogallery | 2017-09-29 | 6.4 MEDIUM | N/A |
useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account. | |||||
CVE-2008-2347 | 1 Mypicgallery | 1 Mypicgallery | 2017-09-29 | 7.5 HIGH | N/A |
MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting the userID parameter to "admin" in a direct request to admin/addUser.php. | |||||
CVE-2008-2298 | 1 Sourceforge | 1 Web Slider | 2017-09-29 | 7.5 HIGH | N/A |
Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1. | |||||
CVE-2008-4081 | 1 Stash | 1 Stash | 2017-09-29 | 7.5 HIGH | N/A |
admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie. | |||||
CVE-2008-2282 | 1 Thomas Voecking | 1 Internet Photoshow | 2017-09-29 | 7.5 HIGH | N/A |
admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admin cookie to true. | |||||
CVE-2008-3317 | 1 Maian Script World | 1 Maian Search | 2017-09-29 | 7.5 HIGH | N/A |
admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary search_cookie cookie. | |||||
CVE-2008-2920 | 1 Ezcms | 1 Eztechhelp Ezcms | 2017-09-29 | 7.5 HIGH | N/A |
admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files. | |||||
CVE-2008-3407 | 1 Phplinkat | 1 Phplinkat | 2017-09-29 | 5.0 MEDIUM | N/A |
phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie. | |||||
CVE-2008-3815 | 1 Cisco | 2 Asa 5500, Pix | 2017-09-29 | 4.3 MEDIUM | N/A |
Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)3, 7.1 before 7.1(2)78, 7.2 before 7.2(4)16, 8.0 before 8.0(4)6, and 8.1 before 8.1(1)13, when configured as a VPN using Microsoft Windows NT Domain authentication, allows remote attackers to bypass VPN authentication via unknown vectors. | |||||
CVE-2008-3292 | 1 Ezwebalbum | 1 Ezwebalbum | 2017-09-29 | 6.4 MEDIUM | N/A |
constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin cookie, as demonstrated via addpage.php. | |||||
CVE-2008-2833 | 1 Worldlevel | 1 Le.cms | 2017-09-29 | 10.0 HIGH | N/A |
admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 parameter in conjunction with filenames in the filename and upload parameters. | |||||
CVE-2008-3211 | 1 Scripteen | 1 Free Image Hosting Script | 2017-09-29 | 7.5 HIGH | N/A |
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1. | |||||
CVE-2008-0391 | 1 Alilg | 1 Alitalk | 2017-09-29 | 7.5 HIGH | N/A |
inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conjunction with the ubild and pa parameters. | |||||
CVE-2008-1904 | 1 Cicoandcico | 1 Ccmail | 2017-09-29 | 7.5 HIGH | N/A |
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attackers to obtain access to the "admin area" via a modified this_cookie cookie. | |||||
CVE-2008-0210 | 1 Uebimiau | 1 Webmail | 2017-09-29 | 6.4 MEDIUM | N/A |
Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting. NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140. | |||||
CVE-2008-1868 | 1 Pixel Motion | 1 Pixel Motion Blog | 2017-09-29 | 7.5 HIGH | N/A |
admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information. | |||||
CVE-2008-0351 | 1 Evilsentinel | 1 Evilsentinel | 2017-09-29 | 5.0 MEDIUM | N/A |
admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php. | |||||
CVE-2008-1971 | 1 Phphq | 1 Phshoutbox Final | 2017-09-29 | 7.5 HIGH | N/A |
phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php. | |||||
CVE-2008-1727 | 1 Myknowledgequest | 1 Knowledgequest | 2017-09-29 | 7.5 HIGH | N/A |
KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts. |