7.5
CVSSv2

CVE-2006-5474

Published: 24/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The "forgot password" function in OneOrZero Helpdesk prior to 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote malicious users to gain access as an arbitrary user by requesting a password reset.

Vulnerable Product Search on Vulmon Subscribe to Product

oneorzero oneorzero helpdesk 1.6

oneorzero oneorzero helpdesk 1.6.3

oneorzero oneorzero helpdesk 1.6.4

oneorzero oneorzero helpdesk