Vulnerabilities > CVE-2007-4106 - SQL Injection vulnerability in Pay Roll Time Sheet and Punch Card Application With Web UI Login.ASP

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
codewidgets
exploit available

Summary

SQL injection vulnerability in login.asp in CodeWidgets Pay Roll - Time Sheet and Punch Card Application With Web Interface allows remote attackers to execute arbitrary SQL commands via the Password parameter.

Vulnerable Configurations

Part Description Count
Application
Codewidgets
2

Exploit-Db

descriptionPay Roll Time Sheet and Punch Card Application With Web UI Login.ASP SQL Injection Vulnerability. CVE-2007-4106. Webapps exploit for asp platform
idEDB-ID:30427
last seen2016-02-03
modified2007-07-28
published2007-07-28
reporterAria-Security Team
sourcehttps://www.exploit-db.com/download/30427/
titlePay Roll Time Sheet and Punch Card Application With Web UI Login.ASP SQL Injection Vulnerability