Overview
OneOrZero Action & Information Management System (AIMS) is vulnerable to an authentication bypass and SQL injection.
Description
According to the vendor's website: "OneOrZero AIMS is a powerful enterprise ready suite that includes a help desk, knowledge base, time manager and reporting system supported by a highly configurable and extensible Action & Information Management System that allows you to 'build your own system' on the fly."  | 
Impact
An unauthenticated remote attacker may be able to bypass authentication or leak database information.  | 
Solution
We are currently unaware of a practical solution to this problem.  | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
Thanks to Yuri Goltsev of Positive Technologies for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
| CVE IDs: | None | 
| Severity Metric: | 0.07 | 
| Date Public: | 2011-10-12 | 
| Date First Published: | 2011-10-13 | 
| Date Last Updated: | 2011-10-13 14:49 UTC | 
| Document Revision: | 8 |