Onelook maintains a small portfolio of web applications and e-commerce platforms, including Courts Online, OBOShop, and OneByone CMS, each presenting limited but distinct deployment footprints. The durable signal across disclosures centers on improper authentication mechanisms, reflecting input-validation and access-control challenges common to custom web applications. Current vulnerability counts, severity distributions, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Onelook over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1951HIGH Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. | Apr 11, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-1952HIGH Session fixation vulnerability in onelook onebyone CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. | Apr 11, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-1953HIGH Session fixation vulnerability in onelook courts on-line allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. | Apr 11, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Onelook.
Media articles that mention a CVE ID that affects a product developed by Onelook — matched by CVE ID, not by vendor name.