exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

timetrex-xss.txt

timetrex-xss.txt
Posted Aug 22, 2008
Authored by DoZ | Site hackerscenter.com

TimeTrex suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 91b01bc886e650d69cf7993c90bc77288b70798c898e45c1fae49bf660feaa80

timetrex-xss.txt

Change Mirror Download
[HSC] TimeTrex Time and Attendance Cookie Theft


TimeTrex allows companies to track and monitor employee attendance
accurately in real-time from anywhere

in the world. An attacker may leverage these issues to execute arbitrary
script code in the browser of

an unsuspecting user in the context of the affected site. Attacker can
tricks the user's computer into

running code which is treated as trustworthy because it appears to belong to
the server, allowing the

attacker to obtain a copy of the cookie or perform other operations.



Hackers Center Security Group (https://www.hackerscenter.com)
Credit: Doz

Class: Cross Site Scripting
Remote: Yes

Product: TimeTrex
Vendor: https://www.timetrex.com
Version: N/A


Attackers can exploit these issues via a web client.


https://site.com/interface/Login.php?user_name=admin&password=XSS
https://site.com/interface/Login.php?user_name=XSS





Google Dork: TimeTrex Time and Attendance - Secure Login
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close