CVE-2006-5474
Summary
| CVE | CVE-2006-5474 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-10-24 20:07:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oneorzero | Oneorzero Helpdesk | 1.6 | All | All | All |
| Application | Oneorzero | Oneorzero Helpdesk | 1.6.3 | All | All | All |
| Application | Oneorzero | Oneorzero Helpdesk | 1.6.4 | All | All | All |
| Application | Oneorzero | Oneorzero Helpdesk | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Whitedust.net - The Best security antivirus network Resources and Information. This website is for sale! | af854a3a-2127-422b-91ae-364da2661108 | www.whitedust.net | Exploit, Vendor Advisory |
| OneOrZero Open Source Task Management and Help Desk System Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| oneorzero.com/downloads/release_notes/Current_Release_notes.html | af854a3a-2127-422b-91ae-364da2661108 | oneorzero.com | Patch |
| OneOrZero Helpdesk Insecure Password Generation Security Issue - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Advisory for Oneorzero helpdesk - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.