CVE-2007-6217
Irola My-Time 3.5 - SQL Injection via Login and Password Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6217. PoCs published by Aria-Security Team.
AI-analyzed exploit summary This is a writeup detailing SQL injection vulnerabilities in an unspecified irola.com product, providing example queries to extract database information and modify user credentials. No executable exploit code is present.
Description
Multiple SQL injection vulnerabilities in login.asp in Irola My-Time (aka Timesheet) 3.5 allow remote attackers to execute arbitrary SQL commands via the (1) login (aka Username) and (2) password parameters. NOTE: some of these details are obtained from third party information.
Exploits (1)
This is a writeup detailing SQL injection vulnerabilities in an unspecified irola.com product, providing example queries to extract database information and modify user credentials. No executable exploit code is present.