Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-0707. PoCs published by ViRuSMaN.
AI-analyzed exploit summary This exploit leverages an authentication bypass vulnerability in TimeClock software to add an administrator user remotely. The PoC provides an HTML form that submits a crafted POST request to the vulnerable endpoint.
Description
Cross-site request forgery (CSRF) vulnerability in add_user.php in Employee Timeclock Software 0.99 allows remote attackers to hijack the authentication of an administrator for requests that create new administrative users. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit leverages an authentication bypass vulnerability in TimeClock software to add an administrator user remotely. The PoC provides an HTML form that submits a crafted POST request to the vulnerable endpoint.