Overview
OneOrZero Action & Information Management System (AIMS) is vulnerable to an authentication bypass and SQL injection.
Description
According to the vendor's website: "OneOrZero AIMS is a powerful enterprise ready suite that includes a help desk, knowledge base, time manager and reporting system supported by a highly configurable and extensible Action & Information Management System that allows you to 'build your own system' on the fly." |
Impact
An unauthenticated remote attacker may be able to bypass authentication or leak database information. |
Solution
We are currently unaware of a practical solution to this problem. |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
Acknowledgements
Thanks to Yuri Goltsev of Positive Technologies for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
| CVE IDs: | None |
| Severity Metric: | 0.07 |
| Date Public: | 2011-10-12 |
| Date First Published: | 2011-10-13 |
| Date Last Updated: | 2011-10-13 14:49 UTC |
| Document Revision: | 8 |