Перейти к содержимому
Noroxi

Записи oneorzero

13 опубликованных записей вендора oneorzero.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Все записи

    13 записей
    • CVE-2003-0304
      42В плане

      one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php He

      КритическаяCVSS 10,0Proof of conceptEPSS 8 %

      oneorzero · oneorzero helpdesk9 июн. 2003 г.

    • CVE-2011-4214
      41В плане

      OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator priv

      КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

      oneorzero · aims1 нояб. 2011 г.

    • CVE-2006-5474
      31Наблюдать

      The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      oneorzero · oneorzero helpdesk24 окт. 2006 г.

    • CVE-2011-4215
      30Наблюдать

      SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers t

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      oneorzero · aims1 нояб. 2011 г.

    • CVE-2006-1501
      30Наблюдать

      SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      oneorzero · oneorzero29 мар. 2006 г.

    • CVE-2006-4350
      30Наблюдать

      SQL injection vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to execute arbitrary SQL commands via the id parameter

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      oneorzero · oneorzero24 авг. 2006 г.

    • CVE-2006-4351
      27Наблюдать

      Cross-site scripting (XSS) vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to inject arbitrary web script or HTML vi

      СредняяCVSS 6,8Эксплойта нетEPSS 1 %

      oneorzero · oneorzero24 авг. 2006 г.

    • CVE-2010-4834
      26Наблюдать

      Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticat

      СредняяCVSS 6,5Proof of conceptEPSS 1 %

      oneorzero · aims13 сент. 2011 г.

    • CVE-2009-0886
      22Наблюдать

      Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via

      СредняяCVSS 5,0Proof of conceptEPSS 7 %

      oneorzero · oneorzero helpdesk12 мар. 2009 г.

    • CVE-2003-0303
      21Наблюдать

      SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descri

      СредняяCVSS 5,0Proof of conceptEPSS 3 %

      oneorzero · oneorzero helpdesk9 июн. 2003 г.

    • CVE-2007-5727
      18Наблюдать

      Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other ver

      СредняяCVSS 4,3Эксплойта нетEPSS 2 %

      oneorzero · oneorzero helpdesk30 окт. 2007 г.

    • CVE-2010-4835
      17Наблюдать

      Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary f

      СредняяCVSS 4,0Proof of conceptEPSS 2 %

      oneorzero · aims13 сент. 2011 г.

    • CVE-2012-0989
      17Наблюдать

      Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to i

      СредняяCVSS 4,3Proof of conceptEPSS 2 %

      oneorzero · action and information management system1 окт. 2012 г.