Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-02-15 03:06
Updated : 2018-10-19 08:45
NVD link : CVE-2006-0692
Mitre link : CVE-2006-0692
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
carey_briggs
- php_mysql_timesheet