functional security
Showing 1 - 1 of 1 RSS Feed

Files

Employee Timeclock Software SQL Injection
Posted Mar 10, 2010
Site secunia.com

Secunia Research has discovered some vulnerabilities in Employee Timeclock Software, which can be exploited by malicious people to conduct SQL injection attacks. Input passed to the "username" and "password" parameters in auth.php and login_action.php is not properly sanitized before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Version 0.99 is affected.

tags | advisory, arbitrary, php, vulnerability, sql injection
advisories | CVE-2010-0122
MD5 | 97deca06ff6efb5d59e274ff9355eacb
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close