Skip to content
Noroxi

oneorzero records

13 published records for vendor oneorzero.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

13 records
  • one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php He

    CriticalCVSS 10.0Proof of conceptEPSS 8%

    oneorzero · oneorzero helpdeskJun 9, 2003

  • OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator priv

    CriticalCVSS 10.0No exploitEPSS 3%

    oneorzero · aimsNov 1, 2011

  • CVE-2006-5474
    31Monitor

    The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with

    HighCVSS 7.5No exploitEPSS 2%

    oneorzero · oneorzero helpdeskOct 24, 2006

  • CVE-2011-4215
    30Monitor

    SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers t

    HighCVSS 7.5No exploitEPSS 1%

    oneorzero · aimsNov 1, 2011

  • CVE-2006-1501
    30Monitor

    SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter

    HighCVSS 7.5Proof of conceptEPSS 1%

    oneorzero · oneorzeroMar 29, 2006

  • CVE-2006-4350
    30Monitor

    SQL injection vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to execute arbitrary SQL commands via the id parameter

    HighCVSS 7.5No exploitEPSS 1%

    oneorzero · oneorzeroAug 24, 2006

  • CVE-2006-4351
    27Monitor

    Cross-site scripting (XSS) vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to inject arbitrary web script or HTML vi

    MediumCVSS 6.8No exploitEPSS 1%

    oneorzero · oneorzeroAug 24, 2006

  • CVE-2010-4834
    26Monitor

    Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticat

    MediumCVSS 6.5Proof of conceptEPSS 1%

    oneorzero · aimsSep 13, 2011

  • CVE-2009-0886
    22Monitor

    Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via

    MediumCVSS 5.0Proof of conceptEPSS 7%

    oneorzero · oneorzero helpdeskMar 12, 2009

  • CVE-2003-0303
    21Monitor

    SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descri

    MediumCVSS 5.0Proof of conceptEPSS 3%

    oneorzero · oneorzero helpdeskJun 9, 2003

  • CVE-2007-5727
    18Monitor

    Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other ver

    MediumCVSS 4.3No exploitEPSS 2%

    oneorzero · oneorzero helpdeskOct 30, 2007

  • CVE-2010-4835
    17Monitor

    Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary f

    MediumCVSS 4.0Proof of conceptEPSS 2%

    oneorzero · aimsSep 13, 2011

  • CVE-2012-0989
    17Monitor

    Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to i

    MediumCVSS 4.3Proof of conceptEPSS 2%

    oneorzero · action and information management systemOct 1, 2012