Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2012-2105
Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.005
EPSS Ranking
63.2%
CVSS Severity
CVSS v2 Score
7.5
References
http://archives.neohapsis.com/archives/bugtraq/2012-03/0011.html
http://secunia.com/advisories/48239
http://sourceforge.net/apps/mantisbt/tsheetx/view.php?id=122
http://www.exploit-db.com/exploits/18554
http://www.openwall.com/lists/oss-security/2012/04/16/4
http://www.openwall.com/lists/oss-security/2012/04/16/7
http://www.osvdb.org/79804
http://www.securityfocus.com/bid/52270
https://exchange.xforce.ibmcloud.com/vulnerabilities/73680
http://archives.neohapsis.com/archives/bugtraq/2012-03/0011.html
http://secunia.com/advisories/48239
http://sourceforge.net/apps/mantisbt/tsheetx/view.php?id=122
http://www.exploit-db.com/exploits/18554
http://www.openwall.com/lists/oss-security/2012/04/16/4
http://www.openwall.com/lists/oss-security/2012/04/16/7
http://www.osvdb.org/79804
http://www.securityfocus.com/bid/52270
https://exchange.xforce.ibmcloud.com/vulnerabilities/73680
Products affected by CVE-2012-2105
Peter Kovacs
»
Timesheet Next Gen
»
Version:
1.5.2
cpe:2.3:a:peter_kovacs:timesheet_next_gen:1.5.2
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved