TTS Software Time Tracking Software Edituser.PHP Access Validation Vulnerability
BID:16731
Info
TTS Software Time Tracking Software Edituser.PHP Access Validation Vulnerability
| Bugtraq ID: | 16731 |
| Class: | Access Validation Error |
| CVE: |
CVE-2006-0689 CVE-2006-0690 CVE-2006-0691 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2006 12:00AM |
| Updated: | Feb 22 2006 06:12PM |
| Credit: | Aliaksandr Hartsuyeu is credited with the discovery of this vulnerability. |
| Vulnerable: |
Schedulingmanagement Time Tracking Software 3.0 |
| Not Vulnerable: | |
Discussion
TTS Software Time Tracking Software Edituser.PHP Access Validation Vulnerability
Time Tracking Software is prone to an access-validation vulnerability. This issue is due the application's failure to limit access to administrative sections of the application.
An attacker can exploit this vulnerability to modify user data in the context of the application. This may result in a loss of confidentiality. The attacker may use this information in further attacks.
This issue is reported to affect Time Tracking Software version 3.0; other versions may also be vulnerable.
Time Tracking Software is prone to an access-validation vulnerability. This issue is due the application's failure to limit access to administrative sections of the application.
An attacker can exploit this vulnerability to modify user data in the context of the application. This may result in a loss of confidentiality. The attacker may use this information in further attacks.
This issue is reported to affect Time Tracking Software version 3.0; other versions may also be vulnerable.
Exploit / POC
TTS Software Time Tracking Software Edituser.PHP Access Validation Vulnerability
An exploit is not required.
An example URI has been provided:
http://www.example.com/timetracking/edituser.php? num=[userid]
An exploit is not required.
An example URI has been provided:
http://www.example.com/timetracking/edituser.php? num=[userid]
Solution / Fix
TTS Software Time Tracking Software Edituser.PHP Access Validation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
TTS Software Time Tracking Software Edituser.PHP Access Validation Vulnerability
References:
References:
- Time Tracking Software Web Site (Schedulingmanagement)
- [eVuln] Time Tracking Software Multiple Vulnerabilities (eVuln.com)