oneorzero records
13 published records for vendor oneorzero.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2003-0304Proof of concept | one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Heoneorzero · oneorzero helpdesk | Critical10.0 | — | 8.1% | Jun 9, 2003 |
41Plan | CVE-2011-4214No exploit | OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privoneorzero · aims · CWE-287 | Critical10.0 | — | 3.1% | Nov 1, 2011 |
31Monitor | CVE-2006-5474No exploit | The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp withoneorzero · oneorzero helpdesk | High7.5 | — | 1.8% | Oct 24, 2006 |
30Monitor | CVE-2011-4215No exploit | SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers toneorzero · aims · CWE-89 | High7.5 | — | 1.3% | Nov 1, 2011 |
30Monitor | CVE-2006-1501Proof of concept | SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameteroneorzero · oneorzero · CWE-89 | High7.5 | — | 1.3% | Mar 29, 2006 |
30Monitor | CVE-2006-4350No exploit | SQL injection vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to execute arbitrary SQL commands via the id parameteroneorzero · oneorzero | High7.5 | — | 1.2% | Aug 24, 2006 |
27Monitor | CVE-2006-4351No exploit | Cross-site scripting (XSS) vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to inject arbitrary web script or HTML vioneorzero · oneorzero | Medium6.8 | — | 1.2% | Aug 24, 2006 |
26Monitor | CVE-2010-4834Proof of concept | Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticatoneorzero · aims · CWE-89 | Medium6.5 | — | 0.9% | Sep 13, 2011 |
22Monitor | CVE-2009-0886Proof of concept | Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files viaoneorzero · oneorzero helpdesk · CWE-22 | Medium5.0 | — | 6.5% | Mar 12, 2009 |
21Monitor | CVE-2003-0303Proof of concept | SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descrioneorzero · oneorzero helpdesk | Medium5.0 | — | 2.5% | Jun 9, 2003 |
18Monitor | CVE-2007-5727No exploit | Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other veroneorzero · oneorzero helpdesk · CWE-79 | Medium4.3 | — | 1.9% | Oct 30, 2007 |
17Monitor | CVE-2010-4835Proof of concept | Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary foneorzero · aims · CWE-22 | Medium4.0 | — | 2.3% | Sep 13, 2011 |
17Monitor | CVE-2012-0989Proof of concept | Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to ioneorzero · action and information management system · CWE-79 | Medium4.3 | — | 1.6% | Oct 1, 2012 |
- CVE-2003-030442Plan
one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php He
CriticalCVSS 10.0Proof of conceptEPSS 8%oneorzero · oneorzero helpdeskJun 9, 2003
- CVE-2011-421441Plan
OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator priv
CriticalCVSS 10.0No exploitEPSS 3%oneorzero · aimsNov 1, 2011
- CVE-2006-547431Monitor
The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with
HighCVSS 7.5No exploitEPSS 2%oneorzero · oneorzero helpdeskOct 24, 2006
- CVE-2011-421530Monitor
SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers t
HighCVSS 7.5No exploitEPSS 1%oneorzero · aimsNov 1, 2011
- CVE-2006-150130Monitor
SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter
HighCVSS 7.5Proof of conceptEPSS 1%oneorzero · oneorzeroMar 29, 2006
- CVE-2006-435030Monitor
SQL injection vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to execute arbitrary SQL commands via the id parameter
HighCVSS 7.5No exploitEPSS 1%oneorzero · oneorzeroAug 24, 2006
- CVE-2006-435127Monitor
Cross-site scripting (XSS) vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to inject arbitrary web script or HTML vi
MediumCVSS 6.8No exploitEPSS 1%oneorzero · oneorzeroAug 24, 2006
- CVE-2010-483426Monitor
Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticat
MediumCVSS 6.5Proof of conceptEPSS 1%oneorzero · aimsSep 13, 2011
- CVE-2009-088622Monitor
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via
MediumCVSS 5.0Proof of conceptEPSS 7%oneorzero · oneorzero helpdeskMar 12, 2009
- CVE-2003-030321Monitor
SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descri
MediumCVSS 5.0Proof of conceptEPSS 3%oneorzero · oneorzero helpdeskJun 9, 2003
- CVE-2007-572718Monitor
Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other ver
MediumCVSS 4.3No exploitEPSS 2%oneorzero · oneorzero helpdeskOct 30, 2007
- CVE-2010-483517Monitor
Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary f
MediumCVSS 4.0Proof of conceptEPSS 2%oneorzero · aimsSep 13, 2011
- CVE-2012-098917Monitor
Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to i
MediumCVSS 4.3Proof of conceptEPSS 2%oneorzero · action and information management systemOct 1, 2012