Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-1053. PoCs published by cr4wl3r.
AI-analyzed exploit summary The exploit demonstrates an SQL injection vulnerability in Zen Tracking <= 2.2, allowing authentication bypass via crafted input in the login forms. The PoC provides specific payloads for both user and manager login pages.
Description
Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to (a) userlogin.php and (b) managerlogin.php. NOTE: some of these details are obtained from third party information.
Exploits (1)
The exploit demonstrates an SQL injection vulnerability in Zen Tracking <= 2.2, allowing authentication bypass via crafted input in the login forms. The PoC provides specific payloads for both user and manager login pages.