timeclock-software kayıtları
timeclock-software üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-255 Credentials Management Errors1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2010-0122Kavram kanıtı | Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the timeclock-software · employee timeclock software · CWE-89 | Yüksek7,5 | — | %2,3 | 15 Mar 2010 |
27İzleyin | CVE-2010-0707Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in add_user.php in Employee Timeclock Software 0.99 allows remote attackers to hijack the autimeclock-software · employee timeclock software · CWE-352 | Orta6,8 | — | %1,0 | 25 Şub 2010 |
20İzleyin | CVE-2010-0123İstismar yok | The database backup implementation in Employee Timeclock Software 0.99 stores sensitive information under the web root with insufficient acctimeclock-software · employee timeclock software · CWE-264 | Orta5,0 | — | %1,3 | 15 Mar 2010 |
8İzleyin | CVE-2010-0124İstismar yok | Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive intimeclock-software · employee timeclock software · CWE-255 | Düşük2,1 | — | %0,4 | 15 Mar 2010 |
- CVE-2010-012231İzleyin
Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the
YüksekCVSS 7,5Kavram kanıtıEPSS %2timeclock-software · employee timeclock software15 Mar 2010
- CVE-2010-070727İzleyin
Cross-site request forgery (CSRF) vulnerability in add_user.php in Employee Timeclock Software 0.99 allows remote attackers to hijack the au
OrtaCVSS 6,8Kavram kanıtıEPSS %1timeclock-software · employee timeclock software25 Şub 2010
- CVE-2010-012320İzleyin
The database backup implementation in Employee Timeclock Software 0.99 stores sensitive information under the web root with insufficient acc
OrtaCVSS 5,0İstismar yokEPSS %1timeclock-software · employee timeclock software15 Mar 2010
- CVE-2010-01248İzleyin
Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive in
DüşükCVSS 2,1İstismar yokEPSS %0timeclock-software · employee timeclock software15 Mar 2010