Timesheet Blind SQL Injection Vulnerability Timesheet Blind SQL Injection Vulnerability

Reviews
Timesheet 1.2.1 Blind SQL Injection Vulnerability Timesheet 1.2.1 Blind SQL Injection Vulnerability Source: http://www.derkeiler.com/Mailing−Lists/securityfocus/bugtraq/2006−09/msg00126.html • From: secaware2006@xxxxxxxxx • Date: 5 Sep 2006 19:56:10 −0000 About: Timesheet.php is a PHP application designed to keep track of the hours worked by multiple people on multiple projects. It allows users to log in through their web browser and manage the times that they are clocked on or clocked off. Description: A vulnerability can be found on the file login.php on $_POST['username'] variable. When magic_quotes_gpc is set to Off an intruder can trigger a blind sql injection. Escalation: 1. Disclosure of administrator username and password hash (MD5, PASSWORD) credentials. 2. Remote code execution in case the intruder knows where to save the output of the sql injection on the local path. Solution: Create addslashes function that will filter the $_POST and $_GET variables. Vendor: http://sourceforge.net/projects/tsheet dwayner79 at users.sourceforge.net vexil at users.sourceforge.net Time table: Notified: 09/04/2006 Response: No Response Public disclosure: 09/05/2006 Updates: N/A Credits: Research By: Secaware Research Research Site: http://secaware.blogspot.com Research Mail: secaware2006 at yahoo dot com Timesheet 1.2.1 Blind SQL Injection Vulnerability 1 Timesheet 1.2.1 Blind SQL Injection Vulnerability References: http://secaware.blogspot.com/2006/09/timesheet−121−blind−sql−injection.html Timesheet 1.2.1 Blind SQL Injection Vulnerability 2

Related docs
timesheet 121
Views: 14  |  Downloads: 0
TimeSheet 131
Views: 0  |  Downloads: 0
TIMESHEET 225
Views: 3  |  Downloads: 0
Timesheet 175
Views: 1  |  Downloads: 0
TIMESHEET 144
Views: 21  |  Downloads: 0
2008-2009 TIMESHEET
Views: 3  |  Downloads: 0
Web Timesheet Release Note
Views: 2  |  Downloads: 0
Timesheet Template - Excel Timesheet
Views: 8761  |  Downloads: 603
Timesheet
Views: 1958  |  Downloads: 83
TimeSheet Professional System Requirements
Views: 23  |  Downloads: 0
TimeSheet
Views: 31  |  Downloads: 5
Other docs by a leitner
FINAL NOTICE BEFORE LEGAL ACTION
Views: 427  |  Downloads: 5
To make multi year lease
Views: 238  |  Downloads: 0
Compensation
Views: 281  |  Downloads: 12
Brown v Board of Education info
Views: 198  |  Downloads: 0
MumbaiUni_cet_cand_data
Views: 10233  |  Downloads: 34
Foreign applications
Views: 227  |  Downloads: 3
Formats for Names in Legal Forms
Views: 514  |  Downloads: 18
Wallops Island Ballon
Views: 187  |  Downloads: 0
Collateral control agreement
Views: 208  |  Downloads: 1
Carrying on business
Views: 253  |  Downloads: 2
Certificate of partnership
Views: 216  |  Downloads: 4
Notice of Directors Meeting
Views: 139  |  Downloads: 3