7.5
CVE-2006-5474
- EPSS 1.84%
- Veröffentlicht 24.10.2006 20:07:00
- Zuletzt bearbeitet 16.06.2026 22:31:16
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oneorzero ≫ Oneorzero Helpdesk Version <= 1.6.5.3
Oneorzero ≫ Oneorzero Helpdesk Version1.6
Oneorzero ≫ Oneorzero Helpdesk Version1.6.3
Oneorzero ≫ Oneorzero Helpdesk Version1.6.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.84% | 0.762 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://oneorzero.com/downloads/release_notes/Current_Release_notes.html
http://secunia.com/advisories/22476
http://securityreason.com/securityalert/1767
http://www.securityfocus.com/archive/1/449352/100/0/threaded
http://www.securityfocus.com/bid/20651
http://www.whitedust.net/speaks/3043/