CVE-2007-6217

Irola My-Time <3.5 - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities in login.asp in Irola My-Time (aka Timesheet) 3.5 allow remote attackers to execute arbitrary SQL commands via the (1) login (aka Username) and (2) password parameters. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Aria-Security Team · textwebappsphp
https://www.exploit-db.com/exploits/4649

Scores

EPSS 0.0126
EPSS Percentile 79.2%

Classification

CWE
CWE-89
Status draft

Affected Products (1)

irola/my-time

Timeline

Published Dec 04, 2007
Tracked Since Feb 18, 2026