Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2006-02-15 11:06
Updated : 2018-10-19 15:45
NVD link : CVE-2006-0692
Mitre link : CVE-2006-0692
CVE.ORG link : CVE-2006-0692
JSON object : View
Products Affected
carey_briggs
- php_mysql_timesheet
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')