CVE-2010-0122 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.31% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-03-15 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| timeclock-software | employee timeclock software |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Employee TimeClock Software 0.99 - SQL Injection | 2010-03-10 |
References
- http://secunia.com/advisories/38739
- http://secunia.com/secunia_research/2010-11/
- http://www.osvdb.org/62831
- http://www.osvdb.org/62832
- http://www.securityfocus.com/archive/1/509995/100/0/threaded
- http://www.securityfocus.com/bid/38639
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56799
- http://secunia.com/advisories/38739
- http://secunia.com/secunia_research/2010-11/
- http://www.osvdb.org/62831
- http://www.osvdb.org/62832
- http://www.securityfocus.com/archive/1/509995/100/0/threaded
- http://www.securityfocus.com/bid/38639
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56799
→ the Explorer · watch your stack · NVD