vendor:
Employee Timeclock Software
by:
Secunia Research
9
CVSS
CRITICAL
SQL Injection
CWE
Product Name: Employee Timeclock Software
Affected Version From: 0.99
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2010
Employee Timeclock Software SQL Injection Vulnerabilities
This vulnerability allows malicious individuals to conduct SQL injection attacks by exploiting input passed to the 'username' and 'password' parameters in auth.ph