Логотип exploitDog
bind:CVE-2020-37005
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-37005

Количество 2

Количество 2

nvd логотип

CVE-2020-37005

10 дней назад

TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject conditional time delays in the add_entry.php endpoint to determine user existence by measuring response time differences.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-hfq2-v7vg-r2m2

10 дней назад

TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject conditional time delays in the add_entry.php endpoint to determine user existence by measuring response time differences.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-37005

TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject conditional time delays in the add_entry.php endpoint to determine user existence by measuring response time differences.

CVSS3: 7.1
0%
Низкий
10 дней назад
github логотип
GHSA-hfq2-v7vg-r2m2

TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject conditional time delays in the add_entry.php endpoint to determine user existence by measuring response time differences.

CVSS3: 7.1
0%
Низкий
10 дней назад

Уязвимостей на страницу