Loading...
Loading...
The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.
October 24, 2006
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2006-5474
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.