vendor:
Pay Roll Time Sheet & Punch Card
by:
L0rd CrusAd3r aka VSN
6,4
CVSS
MEDIUM
Authentication ByPass Vulnerability
287
CWE
Product Name: Pay Roll Time Sheet & Punch Card
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Comriesoftware Pay Roll Time Sheet & Punch Card Authentication Bypass Vulnerability
Microsoft Access 2000/XPASP web Interface includes all source code and demo data. Punch Card calculates hours from time in to time out and can span across days, Calculates Regular Hours, Overtime Hours and Statutory Hours. Code: ASP 3.0 & VBScript. The vulnerability is an Authentication ByPass Vulnerability with the pattern ' or 1=1 or ''=''. The demo URL is http://server/login.asp.
Mitigation:
Ensure that authentication is properly implemented and that user input is properly validated.