Timeclock / Employee Timeclock Software
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2010-0124 | Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listin… | LOW | 2.1 | Mar 12, 2010 |
| CVE-2010-0123 | The database backup implementation in Employee Timeclock Software 0.99 stores sensitive information under the web root with insufficient access control, which… | MEDIUM | 5.0 | Mar 12, 2010 |
| CVE-2010-0122 | Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2)… | HIGH | 7.5 | Mar 12, 2010 |
| CVE-2010-0707 | Cross-site request forgery (CSRF) vulnerability in add_user.php in Employee Timeclock Software 0.99 allows remote attackers to hijack the authentication of an… | MEDIUM | 6.8 | Feb 25, 2010 |
Showing 1 to 4 of 4 CVEs