Overview
OneOrZero Action & Information Management System (AIMS) is vulnerable to an authentication bypass and SQL injection.
Description
According to the vendor's website: "OneOrZero AIMS is a powerful enterprise ready suite that includes a help desk, knowledge base, time manager and reporting system supported by a highly configurable and extensible Action & Information Management System that allows you to 'build your own system' on the fly." |
Impact
An unauthenticated remote attacker may be able to bypass authentication or leak database information. |
Solution
We are currently unaware of a practical solution to this problem. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Yuri Goltsev of Positive Technologies for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | None |
Severity Metric: | 0.07 |
Date Public: | 2011-10-12 |
Date First Published: | 2011-10-13 |
Date Last Updated: | 2011-10-13 14:49 UTC |
Document Revision: | 8 |