7.5
CVE-2006-5474
- EPSS 1.41%
- Veröffentlicht 24.10.2006 20:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oneorzero ≫ Oneorzero Helpdesk Version <= 1.6.5.3
Oneorzero ≫ Oneorzero Helpdesk Version1.6
Oneorzero ≫ Oneorzero Helpdesk Version1.6.3
Oneorzero ≫ Oneorzero Helpdesk Version1.6.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.41% | 0.799 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|