The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2006-10-24T20:00:00
Updated: 2018-10-17T20:57:01
Reserved: 2006-10-24T00:00:00
Link: CVE-2006-5474
JSON object: View
NVD Information
Status : Modified
Published: 2006-10-24T20:07:00.000
Modified: 2018-10-17T21:43:30.033
Link: CVE-2006-5474
JSON object: View
Redhat Information
No data.
CWE