Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
TimeTrex Time and Attendance Cookie Theft Aug 21 2008 04:50PM
DoZ HackersCenter com (2 replies)
[HSC] TimeTrex Time and Attendance Cookie Theft

TimeTrex allows companies to track and monitor employee attendance accurately in real-time from anywhere

in the world. An attacker may leverage these issues to execute arbitrary script code in the browser of

an unsuspecting user in the context of the affected site. Attacker can tricks the user's computer into

running code which is treated as trustworthy because it appears to belong to the server, allowing the

attacker to obtain a copy of the cookie or perform other operations.

Hackers Center Security Group (http://www.hackerscenter.com)

Credit: Doz

Class: Cross Site Scripting

Remote: Yes

Product: TimeTrex

Vendor: http://www.timetrex.com

Version: N/A

Attackers can exploit these issues via a web client.

http://site.com/interface/Login.php?user_name=admin&password=XSS

http://site.com/interface/Login.php?user_name=XSS

Google Dork: TimeTrex Time and Attendance - Secure Login

Reference:

http://www.hackerscenter.com/index.php?/HSC-Research-Group/Advisories/HS
C-TimeTrex-Time-and-Attendance-Cookie-Theft.html

[ reply ]
Re: TimeTrex Time and Attendance Cookie Theft Aug 22 2008 10:49PM
Mike (ipso snappymail ca)
RE: TimeTrex Time and Attendance Cookie Theft Aug 21 2008 09:09PM
Alex Eden (Alex Eden senet-int com)







 

Privacy Statement
Copyright 2009, SecurityFocus