CVE-2010-0122 | Timeclock Employee Timeclock Software 0.99 Login auth.php Password sql injection (EDB-39427 / XFDB-56799)
A vulnerability classified as critical has been found in Timeclock Employee Timeclock Software 0.99. Affected is an unknown function of the file auth.php of the component Login. The manipulation of the argument Password leads to sql injection.
This vulnerability is traded as CVE-2010-0122. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to add further authentication.