Description
TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject conditional time delays in the add_entry.php endpoint to determine user existence by measuring response time differences.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
François Bibeau
References
www.exploit-db.com/exploits/48874 (ExploitDB-48874)
web.archive.org/...0104104315/http://timeclock-software.net/ (Archived Product Homepage)
www.vulncheck.com/...-authenticated-time-based-sql-injection (VulnCheck Advisory: TimeClock Software 1.01 Authenticated Time-Based SQL Injection)