Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aims HIGH 10.0
CVE-2011-4214

OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges vi…

Mitigation only
Fix from $1,950 2011-11-01
Aims HIGH 7.5
CVE-2011-4215

SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to execute…

Mitigation only
Fix from $1,950 2011-11-01
Aims MEDIUM 6.5
CVE-2010-4834

Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users …

No fix yet
Fix from $1,600 2011-09-14
Oneorzero Helpdesk MEDIUM 5.0
CVE-2009-0886EPSS 7%

Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (do…

Fix: after 1.6.5.7
Fix from $1,600 2009-03-12
Oneorzero Helpdesk HIGH 7.5
CVE-2006-5474

The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the user…

Fix: after 1.6.5.3
Fix from $1,950 2006-10-24
Oneorzero HIGH 7.5
CVE-2006-4350

SQL injection vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Mitigation only
Fix from $1,950 2006-08-24
Oneorzero MEDIUM 6.8
CVE-2006-4351

Cross-site scripting (XSS) vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to inject arbitrary web script or HTML via the id …

Mitigation only
Fix from $1,600 2006-08-24
Oneorzero HIGH 7.5
CVE-2006-1501

SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibl…

No fix yet
Fix from $1,950 2006-03-30
Oneorzero Helpdesk HIGH 10.0
CVE-2003-0304EPSS 8%

one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk In…

Patch available
Fix from $1,950 2003-06-09
Oneorzero Helpdesk MEDIUM 5.0
CVE-2003-0303

SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions vi…

Patch available
Fix from $1,600 2003-06-09