CVE-2010-0122
Published Mar 15, 2010
Last updated 6 years ago
Overview
- Description
- Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php.
- Source
- PSIRT-CNA@flexerasoftware.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:timeclock-software:employee_timeclock_software:0.99:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "457072F3-3F76-4197-89C6-F5EA21EC28F8" } ], "operator": "OR" } ] } ]