CVE-2007-6217
Irola My-Time <3.5 - SQL Injection
Title source: llmDescription
Multiple SQL injection vulnerabilities in login.asp in Irola My-Time (aka Timesheet) 3.5 allow remote attackers to execute arbitrary SQL commands via the (1) login (aka Username) and (2) password parameters. NOTE: some of these details are obtained from third party information.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Aria-Security Team · textwebappsphp
https://www.exploit-db.com/exploits/4649
References (8)
Scores
EPSS
0.0126
EPSS Percentile
79.2%
Classification
CWE
CWE-89
Status
draft
Affected Products (1)
irola/my-time
Timeline
Published
Dec 04, 2007
Tracked Since
Feb 18, 2026