VendorsOneorZerooneorzero_helpdeskall versions
Vulnerabilities

OneorZero Oneorzero Helpdesk

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2003-0304
one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script.
Published 2003-05-17 · Modified
10.01 PoCEPSS 0.081
CVE-2006-5474
The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.
Published 2006-10-24 · Modified
7.5EPSS 0.018
CVE-2009-0886
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the default_language parameter.
Published 2009-03-12 · Modified
5.01 PoCEPSS 0.065
CVE-2003-0303
SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.
Published 2003-05-17 · Modified
5.01 PoCEPSS 0.025
CVE-2007-5727
Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description parameter to (1) tcreate.php or (2) tupdate.php, as demonstrated using an onmouseover event in a b tag.
Published 2007-10-30 · Modified
4.3EPSS 0.019