cpe:/a:truworthit:flex_timesheet CVE-2010-4797 2011-04-26T20:55:03.583-04:00 2017-08-16T21:33:21.977-04:00 7.5 NETWORK LOW NONE PARTIAL PARTIAL PARTIAL http://nvd.nist.gov 2011-04-27T10:09:00.000-04:00 EXPLOIT-DB 15220 SECUNIA 41763 BID 43886 SREASON 8222 XF flex-timesheet-username-sql-injection(62374) MISC http://packetstormsecurity.org/1010-exploits/flextimesheet-sql.txt Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.