Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-4926. PoCs published by Salvatore Fresta.
AI-analyzed exploit summary The document describes SQL injection vulnerabilities in TimeTrack 1.2.4 for Joomla, where numeric parameters are not sanitized, allowing arbitrary SQL code execution. It includes a sample exploit URL demonstrating a UNION-based SQL injection to extract user credentials.
Description
SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ct_id parameter in a timetrack action to index.php.
Exploits (1)
The document describes SQL injection vulnerabilities in TimeTrack 1.2.4 for Joomla, where numeric parameters are not sanitized, allowing arbitrary SQL code execution. It includes a sample exploit URL demonstrating a UNION-based SQL injection to extract user credentials.