CVE-2009-2769
Ultrize TimeSheet <1.2.2 - RCE
Title source: llmDescription
PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter.
Exploits (1)
Scores
EPSS
0.0146
EPSS Percentile
80.6%
Classification
CWE
CWE-94
Status
draft
Affected Products (1)
ultrize/timesheet
Timeline
Published
Aug 14, 2009
Tracked Since
Feb 18, 2026