CVE-2020-37005
HIGHTimeClock Software 1.01 - Authenticated SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37005. PoCs published by François Bibeau.
AI-analyzed exploit summary This exploit demonstrates an authenticated time-based SQL injection vulnerability in TimeClock Software 1.01. It uses a SLEEP-based payload to enumerate valid usernames by measuring response delays.
Description
TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject conditional time delays in the add_entry.php endpoint to determine user existence by measuring response time differences.
Exploits (1)
This exploit demonstrates an authenticated time-based SQL injection vulnerability in TimeClock Software 1.01. It uses a SLEEP-based payload to enumerate valid usernames by measuring response delays.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N