Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-5474

EPSS 1.41% · P81
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-5474

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
OneOrZero forgot password函数安全口令重置漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OneOrZero Helpdesk是一个PHP/MySQL帮助桌面软件。 OneOrZero生成访问口令的方式上存在漏洞,攻击者可以利用此漏洞推测出自动生成的口令。 OneOrZero的forgot password函数会在回答完安全问题后重置口令,默认下这个口令为空。用户可以通过重置管理员口令并保持回答为空强制重置口令。但是,由于口令重置函数是基于用户名和服务器时间来设置口令的,因此可以通过服务器的时间来判断所设置的口令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-5474

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-5474

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-10-24 · 20 CVEs total

CVE-2006-5475Drupal XML解析器多个跨站脚本攻击漏洞
CVE-2006-4573GNU Screen utf8组合字符处理多个不明漏洞
CVE-2006-4510Novell eDirectory LDAP服务evtFilteredMonitorEventsRequest函数任意代码执行漏洞
CVE-2006-4509Novell eDirectory evtFilteredMonitorEventsRequest函数整数溢出漏洞
CVE-2006-5481Castor多个PHP远程文件包含漏洞
CVE-2006-5480Castor 'lib/rs.php' PHP远程文件包含漏洞
CVE-2006-5479Novell eDirectory NCP引擎拒绝服务漏洞
CVE-2006-5478Novell eDirectory/iMonitor HTTPSTK栈缓冲区溢出漏洞
CVE-2006-5477Drupal 特制的URL未明跨站脚本攻击漏洞
CVE-2006-5476Drupal 未授权跨站请求伪造漏洞
CVE-2006-5482FreeBSD 'ufs_vnops.c' ftruncate函数本地拒绝服务漏洞
CVE-2006-5473Softerra PHP Developer Library 'Description.php'PHP远程文件包含漏洞
CVE-2006-5472Softerra PHP Developer Library PHP远程文件包含漏洞
CVE-2006-5471Softerra PHP Developer Library 'grid3.lib.php'PHP远程文件包含漏洞
CVE-2006-4177Novell eDirectory NCP数据包处理远程堆溢出漏洞
CVE-2006-5486Sun Java System/iPlanet Messaging Server Webmail中的跨站脚本攻击漏洞
CVE-2006-5485SpeedBerg SPEEDBERG_PATH多个远程文件包含漏洞
CVE-2006-5484多款SSH Communications Security产品安全漏洞
CVE-2006-5483FreeBSD Scheduler策略本地拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2006-5474

No comments yet


Leave a comment