Timeclock-software

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    2
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-37005

    TimeClock Software 1.01 Authenticated Time-Based SQL Injection

    Last Modified: Apr 15, 2026
    Published: Jan 29, 2026

    CVE-2010-0122

    Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php.

    Last Modified: Apr 11, 2025
    Published: Mar 12, 2010

    CVE-2010-0123

    The database backup implementation in Employee Timeclock Software 0.99 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a "semi-predictable file name."

    Last Modified: Apr 11, 2025
    Published: Mar 12, 2010

    CVE-2010-0124

    Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.

    Last Modified: Apr 11, 2025
    Published: Mar 12, 2010

    CVE-2010-0707

    Cross-site request forgery (CSRF) vulnerability in add_user.php in Employee Timeclock Software 0.99 allows remote attackers to hijack the authentication of an administrator for requests that create new administrative users. NOTE: some of these details are obtained from third party information.

    Last Modified: Apr 11, 2025
    Published: Feb 25, 2010
    Items Per Page
    Timeclock-Software Vulnerabilities & Security CVEs | CVE-DB