header-logo
Suggest Exploit
vendor:
Time Tracking Software
by:
SecurityFocus
3.3
CVSS
MEDIUM
Access Validation Vulnerability
285
CWE
Product Name: Time Tracking Software
Affected Version From: 3
Affected Version To: 3
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005

Time Tracking Software Access Validation Vulnerability

Time Tracking Software is prone to an access-validation vulnerability. This issue is due the application's failure to limit access to administrative sections of the application. An attacker can exploit this vulnerability to modify user data in the context of the application. This may result in a loss of confidentiality. The attacker may use this information in further attacks.

Mitigation:

Ensure that access to administrative sections of the application is properly restricted and authenticated.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/16731/info

Time Tracking Software is prone to an access-validation vulnerability. This issue is due the application's failure to limit access to administrative sections of the application. 

An attacker can exploit this vulnerability to modify user data in the context of the application. This may result in a loss of confidentiality. The attacker may use this information in further attacks. 

This issue is reported to affect Time Tracking Software version 3.0; other versions may also be vulnerable.

http://www.example.com/timetracking/edituser.php? num=[userid]