{"api_version":"1","generated_at":"2026-07-23T08:46:07+00:00","cve":"CVE-2010-0122","urls":{"html":"https://cve.report/CVE-2010-0122","api":"https://cve.report/api/cve/CVE-2010-0122.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-0122","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-0122"},"summary":{"title":"CVE-2010-0122","description":"Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php.","state":"PUBLISHED","assigner":"flexera","published_at":"2010-03-15 13:28:25","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-89","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/secunia_research/2010-11/","name":"http://secunia.com/secunia_research/2010-11/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Research - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56799","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56799","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/62831","name":"http://www.osvdb.org/62831","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/38639","name":"http://www.securityfocus.com/bid/38639","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Timeclock Software 'login_action.php' Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/38739","name":"http://secunia.com/advisories/38739","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Employee Timeclock Software Multiple Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/62832","name":"http://www.osvdb.org/62832","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/509995/100/0/threaded","name":"http://www.securityfocus.com/archive/1/509995/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-0122","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-0122","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"122","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"timeclock-software","cpe5":"employee_timeclock_software","cpe6":"0.99","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:37:53.904Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"38639","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/38639"},{"name":"38739","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38739"},{"name":"timeclock-auth-sql-injection(56799)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56799"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2010-11/"},{"name":"62832","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/62832"},{"name":"62831","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/62831"},{"name":"20100310 Secunia Research: Employee Timeclock Software SQL Injection Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/509995/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-03-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","shortName":"flexera"},"references":[{"name":"38639","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/38639"},{"name":"38739","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38739"},{"name":"timeclock-auth-sql-injection(56799)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56799"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2010-11/"},{"name":"62832","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/62832"},{"name":"62831","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/62831"},{"name":"20100310 Secunia Research: Employee Timeclock Software SQL Injection Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/509995/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"PSIRT-CNA@flexerasoftware.com","ID":"CVE-2010-0122","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"38639","refsource":"BID","url":"http://www.securityfocus.com/bid/38639"},{"name":"38739","refsource":"SECUNIA","url":"http://secunia.com/advisories/38739"},{"name":"timeclock-auth-sql-injection(56799)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56799"},{"name":"http://secunia.com/secunia_research/2010-11/","refsource":"MISC","url":"http://secunia.com/secunia_research/2010-11/"},{"name":"62832","refsource":"OSVDB","url":"http://www.osvdb.org/62832"},{"name":"62831","refsource":"OSVDB","url":"http://www.osvdb.org/62831"},{"name":"20100310 Secunia Research: Employee Timeclock Software SQL Injection Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/509995/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","assignerShortName":"flexera","cveId":"CVE-2010-0122","datePublished":"2010-03-12T20:00:00.000Z","dateReserved":"2010-01-04T00:00:00.000Z","dateUpdated":"2024-08-07T00:37:53.904Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-03-15 13:28:25","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-89","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:timeclock-software:employee_timeclock_software:0.99:*:*:*:*:*:*:*","matchCriteriaId":"457072F3-3F76-4197-89C6-F5EA21EC28F8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"122","Ordinal":"1","Title":"CVE-2010-0122","CVE":"CVE-2010-0122","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"122","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php.","Type":"Description","Title":"CVE-2010-0122"},{"CveYear":"2010","CveId":"122","Ordinal":"2","NoteData":"2010-03-12","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"122","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}