cbcvebase.

Oneorzero Aims vulnerabilities

4 known vulnerabilities affecting oneorzero/aims.

Total CVEs
4
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2010-4834P3MEDIUMCVSS 6.5PoCv2.6.0v2.7.02011-09-14
CVE-2010-4834 [MEDIUM] CWE-89 CVE-2010-4834: Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7. Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types parameter in a show_item_search action in the search_management_manage subcontroller. NOTE: some of th
nvd
CVE-2011-4214P3CRITICALCVSS 10.0v2.7.02011-11-01
CVE-2011-4214 [CRITICAL] CWE-287 CVE-2011-4214: OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass auth OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges via a crafted oozimsrememberme cookie.
nvd
CVE-2010-4835P4MEDIUMCVSS 4.0PoCv2.6.02011-09-14
CVE-2010-4835 [MEDIUM] CWE-22 CVE-2010-4835: Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action.
nvd
CVE-2011-4215P3HIGHCVSS 7.5v2.7.02011-11-01
CVE-2011-4215 [HIGH] CWE-89 CVE-2011-4215: SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management Syste SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the cookieName variable.
nvd
Oneorzero Aims vulnerabilities | cvebase