VulnerabilityModified
CVE-2006-4705
SQL injection vulnerability in login.php in dwayner79 and Dominic Gamble Timesheet (aka Timesheet.php) 1.2.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
MEDIUM 5.0EPSS 1.25%
Does this matter?
Lower severity and a low EPSS score (1.25%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in login.php in dwayner79 and Dominic Gamble Timesheet (aka Timesheet.php) 1.2.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.25% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- dominic gamble/timesheet.php
- Source
- cve@mitre.org
References
- http://secaware.blogspot.com/2006/09/timesheet-121-blind-sql-injection.html
- http://secunia.com/advisories/21831
- http://securityreason.com/securityalert/1542
- http://www.securityfocus.com/archive/1/445603/100/0/threaded
- http://www.securityfocus.com/bid/19856
- http://www.vupen.com/english/advisories/2006/3547
- http://secaware.blogspot.com/2006/09/timesheet-121-blind-sql-injection.html
- http://secunia.com/advisories/21831
- http://securityreason.com/securityalert/1542
- http://www.securityfocus.com/archive/1/445603/100/0/threaded
- http://www.securityfocus.com/bid/19856
- http://www.vupen.com/english/advisories/2006/3547
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.