Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown

CVE-2010-4797

Disclosure Date: April 27, 2011 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
0
Attacker Value
Unknown

CVE-2010-2111

Disclosure Date: May 28, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in user/user-set.do in Pacific Timesheet 6.74 build 363 allows remote attackers to hijack the authentication of administrators for requests that create a new administrator via a new_admin action.
0
Attacker Value
Unknown

CVE-2009-3151

Disclosure Date: September 10, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter.
0
Attacker Value
Unknown

CVE-2009-2769

Disclosure Date: August 14, 2009 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter.
0
Attacker Value
Unknown

CVE-2006-4705

Disclosure Date: September 12, 2006 (last updated October 04, 2023)
SQL injection vulnerability in login.php in dwayner79 and Dominic Gamble Timesheet (aka Timesheet.php) 1.2.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
0
Attacker Value
Unknown

CVE-2006-0692

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.
0