CVE-2012-2105 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 1.9% (pctl 79)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 1.92% — more likely to be exploited than 79% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-09-19 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| peter kovacs | timesheet next gen |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Timesheet Next Gen 1.5.2 - Multiple SQL Injections | 2012-03-03 |
References
- http://archives.neohapsis.com/archives/bugtraq/2012-03/0011.html
- http://secunia.com/advisories/48239
- http://sourceforge.net/apps/mantisbt/tsheetx/view.php?id=122
- http://www.exploit-db.com/exploits/18554
- http://www.openwall.com/lists/oss-security/2012/04/16/4
- http://www.openwall.com/lists/oss-security/2012/04/16/7
- http://www.osvdb.org/79804
- http://www.securityfocus.com/bid/52270
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73680
- http://archives.neohapsis.com/archives/bugtraq/2012-03/0011.html
- http://secunia.com/advisories/48239
- http://sourceforge.net/apps/mantisbt/tsheetx/view.php?id=122
- http://www.exploit-db.com/exploits/18554
- http://www.openwall.com/lists/oss-security/2012/04/16/4
- http://www.openwall.com/lists/oss-security/2012/04/16/7
- http://www.osvdb.org/79804
- http://www.securityfocus.com/bid/52270
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73680
→ the Explorer · watch your stack · NVD