CVE-2012-2105
Timesheet Next Gen 1.5.2 - SQL Injection via Username or Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-2105. PoCs published by G13.
AI-analyzed exploit summary This is a writeup describing SQL injection vulnerabilities in Timesheet Next Gen 1.5.2 via the 'username' and 'password' parameters in login.php. It includes a sample HTTP POST request demonstrating the vulnerability but lacks executable exploit code.
Description
Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
Exploits (1)
This is a writeup describing SQL injection vulnerabilities in Timesheet Next Gen 1.5.2 via the 'username' and 'password' parameters in login.php. It includes a sample HTTP POST request demonstrating the vulnerability but lacks executable exploit code.