Official Product Homepageproduct
http://timeclock.sourceforge.net/ CVE-2021-47966
HIGH
PHP Timeclock 1.04 SQL Injection via login.php
Record summary
CVE-2021-47966 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid parameter of login.php that allows unauthenticated attackers to extract database contents. Attackers can submit crafted POST requests with SQL payloads using SLEEP functions or RLIKE conditional statements to dump sensitive database information including employee names and credentials.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 15, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PHP TimeclockBrowse Timeclock / PHP Timeclock | CVE List | 1.04 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBPHP Timeclock 1.04 - Time and Boolean Based Blind SQL InjectionExploitDB exploitby Tyler ButlerNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47966 Product Referenceproduct
https://sourceforge.net/projects/timeclock/files/PHP%20Timeclock/PHP%20Timeclock%201.04 ExploitDB-49849exploit
https://www.exploit-db.com/exploits/49849 VulnCheck Advisory: PHP Timeclock 1.04 SQL Injection via login.phpThird-party advisory
https://www.vulncheck.com/advisories/php-timeclock-sql-injection-via-login-php