HIGH · 7.5

CVE-2006-5474

The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access ...

Vulnerability Description

The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
OneorzeroOneorzero Helpdesk<= 1.6.5.3

References

FAQ

What is CVE-2006-5474?

CVE-2006-5474 is a vulnerability with a CVSS score of 7.5 (HIGH). The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access ...

How severe is CVE-2006-5474?

CVE-2006-5474 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-5474?

Check the references section above for vendor advisories and patch information. Affected products include: Oneorzero Oneorzero Helpdesk.