Lucene search

K
cveMitreCVE-2010-1053
HistoryMar 23, 2010 - 1:00 a.m.

CVE-2010-1053

2010-03-2301:00:00
CWE-89
mitre
web.nvd.nist.gov
35
cve-2010-1053
sql injection
zen time tracking 2.2
security vulnerability
remote code execution

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8.9

Confidence

Low

EPSS

0.001

Percentile

27.8%

Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to (a) userlogin.php and (b) managerlogin.php. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
zentrackingzen_time_trackingRange2.2
VendorProductVersionCPE
zentrackingzen_time_tracking*cpe:2.3:a:zentracking:zen_time_tracking:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8.9

Confidence

Low

EPSS

0.001

Percentile

27.8%

Related for CVE-2010-1053