<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent changes to bugs</title><link>https://sourceforge.net/p/timeclock/bugs/</link><description>Recent changes to bugs</description><atom:link href="https://sourceforge.net/p/timeclock/bugs/feed.rss" rel="self"/><language>en</language><lastBuildDate>Tue, 07 May 2024 12:32:48 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/timeclock/bugs/feed.rss" rel="self" type="application/rss+xml"/><item><title>#18 SQLI/stored XSS vulnerabilities</title><link>https://sourceforge.net/p/timeclock/bugs/18/?limit=25#02d4</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;we further found request race vulnerabilities in version 1.0.4 of the application. Please contact us at ca224test@gmail.com, so we can provide reproducing steps of the vulnerabilities.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ac</dc:creator><pubDate>Tue, 07 May 2024 12:32:48 -0000</pubDate><guid>https://sourceforge.net673c64675259f7fc28daae58e933325b6e06842f</guid></item><item><title>SQLI/stored XSS vulnerabilities</title><link>https://sourceforge.net/p/timeclock/bugs/18/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;To the developers,&lt;/p&gt;
&lt;p&gt;In the progress of our security research project, we found SQLI/stored XSS vulnerabilities in version 1.0.4 of the application. SQLI Related files: groupadmin.php, officeadmin.php. stored XSS related files: display.php, leftmain.php, timeedit.php&lt;/p&gt;
&lt;p&gt;Please contact us at ca224test@gmail.com, so we can provide reproducing steps of the vulnerabilities.&lt;br/&gt;
Thank you.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ac</dc:creator><pubDate>Sun, 04 Dec 2022 19:47:52 -0000</pubDate><guid>https://sourceforge.netbb66742fe10bcb244cbeda41c7f032027fa74847</guid></item><item><title>SQL Injection and Cross Site Scripting Vulnerabilities</title><link>https://sourceforge.net/p/timeclock/bugs/17/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;PHP Timeclock versions 1.04 and prior suffer from serious security vulnerabilities including SQL injection and Cross Site Scripting. This goes without saying but do not use this product anymore in 2021. You can read more about the vulnerabilities here &lt;a href="https://github.com/tcbutler320/PHP-Timeclock-1.04-XSS-SQLI" rel="nofollow"&gt;https://github.com/tcbutler320/PHP-Timeclock-1.04-XSS-SQLI&lt;/a&gt; or on exploit-db here &lt;a href="https://www.exploit-db.com/exploits/49849." rel="nofollow"&gt;https://www.exploit-db.com/exploits/49849.&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tyler Butler</dc:creator><pubDate>Sat, 08 May 2021 12:52:34 -0000</pubDate><guid>https://sourceforge.net744f242f395b956f887cee5ece447cfa688d8d69</guid></item><item><title>SQL Injection and Cross Site Scripting </title><link>https://sourceforge.net/p/timeclock/bugs/16/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;PHP Timeclock versions 1.04 and prior suffer from serious security vulnerabilities including SQL injection and Cross Site Scripting. This goes without saying but do not use this product anymore in 2021. You can read more about the vulnerabilities here &lt;a href="https://github.com/tcbutler320/PHP-Timeclock-1.04-XSS-SQLI" rel="nofollow"&gt;https://github.com/tcbutler320/PHP-Timeclock-1.04-XSS-SQLI&lt;/a&gt; or on exploit-db here &lt;a href="https://www.exploit-db.com/exploits/49849." rel="nofollow"&gt;https://www.exploit-db.com/exploits/49849.&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tyler Butler</dc:creator><pubDate>Sat, 08 May 2021 12:51:04 -0000</pubDate><guid>https://sourceforge.net75252d359a34d24001b32b7124329e525644d86c</guid></item><item><title>1.06 not listed/uploaded to sf.net??</title><link>https://sourceforge.net/p/timeclock/bugs/15/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;new version not released yet to sf.net??? 1.06 out right??&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Zeb Cameron</dc:creator><pubDate>Wed, 15 May 2013 09:15:08 -0000</pubDate><guid>https://sourceforge.net453a1ab022217cee86c65aa096cfc3ea04dae563</guid></item><item><title>PHP 4 &amp; 5 running at same time...</title><link>https://sourceforge.net/p/timeclock/bugs/14/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;adminuser.php and searchuser.php in the admin area have a display problem in the current zip release. I was able to fix the problems myself but you might want to have a look.&lt;/p&gt;
&lt;p&gt;Note: I am running PHP4 and 5 at the same time... not many folks have a need to do this, I'm a developer so I have a use for both.&lt;/p&gt;
&lt;p&gt;Why?&lt;br /&gt;
A lot of appz do not run right under the improved 5 object environment.&lt;/p&gt;
&lt;p&gt;Other than those 2 files everything seems to be pretty tight, great work!&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ernest Buffington</dc:creator><pubDate>Sun, 16 Mar 2008 05:00:20 -0000</pubDate><guid>https://sourceforge.netf451fcfb9f91144b7ce8eb8c03916fb6293f8936</guid></item><item><title>PHP TImeclock Page not Loading Properly...</title><link>https://sourceforge.net/p/timeclock/bugs/13/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;I have as many as 50 people access this PHP Timeclock system.  We have had a reoccurring problem of where the software does not load consistently.&lt;/p&gt;
&lt;p&gt;Page comes up either:&lt;br /&gt;
1) Blank with a white page.&lt;br /&gt;
2) With some type of configuration screen that shows a menu with Apple Talk, NetBeui, NetWare, SNTP, TCP/IP, etc.&lt;br /&gt;
3) A timeout.&lt;/p&gt;
&lt;p&gt;I have restarted the server, as well as restarted the httpd service.  I am unable to determine what is causing this so erratically.&lt;/p&gt;
&lt;p&gt;We have timeclock.mydomain.com as a virtual server pointing to the PHP directory.&lt;/p&gt;
&lt;p&gt;The system is a CentOS 5.0 server with all updates.  RPM packages version are as follows:&lt;/p&gt;
&lt;p&gt;httpd-2.2.3-7.el5.centos&lt;/p&gt;
&lt;p&gt;mysql-5.0.22-2.1&lt;br /&gt;
mysql-server-5.0.22-2.1&lt;/p&gt;
&lt;p&gt;php-mysql-5.1.6-12.el5&lt;br /&gt;
php-5.1.6-12.el5&lt;br /&gt;
php-common-5.1.6-12.el5&lt;br /&gt;
php-cli-5.1.6-12.el5&lt;br /&gt;
php-mbstring-5.1.6-12.el5&lt;br /&gt;
php-ldap-5.1.6-12.el5&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Adrian Anhood</dc:creator><pubDate>Wed, 15 Aug 2007 20:38:52 -0000</pubDate><guid>https://sourceforge.net63adea2a824bb2b6dbd748a77c29eb006cb8471c</guid></item><item><title>Edit Page - Wrong Timestamp Range</title><link>https://sourceforge.net/p/timeclock/bugs/12/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;timeedit.php is only selecting punchitems up unitl 2pm on the day i select.&lt;/p&gt;
&lt;p&gt;Add &amp;amp; Delete work fine, its just Edit that doesn't work&lt;/p&gt;
&lt;p&gt;I'm using 24 hour time format, GMT +10 timezone and euro calendar.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ryan Williams</dc:creator><pubDate>Thu, 17 May 2007 23:42:10 -0000</pubDate><guid>https://sourceforge.net130d856b6f5e9b75b2aa392d8d3522caea27db44</guid></item><item><title>Possible Race Condition</title><link>https://sourceforge.net/p/timeclock/bugs/11/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;leftmain.php line 360 begins s sequence of calls to gmdate. there exists a slight possibility for an error of one hour. (other errors are possible, but not of as great of concern for me :-) )&lt;/p&gt;
&lt;p&gt;consider the following at 4:59:59.65 I punch out.&lt;br /&gt;
at 4:59:59.99 the line $hour = gmdate('H'); is executed.&lt;br /&gt;
at 5:00:00.00 the line $min = gmdate('i'); is executed.&lt;br /&gt;
the recorded punch will read 4:00.&lt;/p&gt;
&lt;p&gt;why not use time()? acording to the php manual &lt;a href="http://us2.php.net/manual/en/function.time.php" rel="nofollow"&gt;http://us2.php.net/manual/en/function.time.php&lt;/a&gt; this is also GMT.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ben</dc:creator><pubDate>Fri, 04 May 2007 20:58:53 -0000</pubDate><guid>https://sourceforge.net96d53de0d4fcbb6b29a9ac28c9f89ce0108314e4</guid></item><item><title>Timeclock mis-handles future time entries</title><link>https://sourceforge.net/p/timeclock/bugs/10/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Timeclock 1.03 errs when future time has been entered.&lt;/p&gt;
&lt;p&gt;I entered time for tomorrow (in and out) before having clocked out for today.  The Out time for tomorrow shows up as the current status on the home page, and both In and Out show up in Edit Time for today's date (as well as where it should be on tomorrow's date).&lt;/p&gt;
&lt;p&gt;Clocking out for today set the current Out status appropriately (Out for today with the correct Out time).&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;Deleting tomorrow's Out (and leaving the In), however, does not set the current status to In with tomorrow's In time.  This, of course, should be expected.&lt;/p&gt;
&lt;p&gt;Furthermore, deleting the last Out for today (the one just entered), thus leaving only an In, removes the user's status completely from the home page - even though one of the Ins should be the current status.  The time must be modified for the user to appear again.&lt;/p&gt;
&lt;p&gt;Apologies if this is confusing as I've just found it out and haven't tried to discover the source error.  If someone else can confirm similar behavior on their installation, I'd appreciate it.&lt;/p&gt;
&lt;p&gt;Let me know if further details are necessary.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tom Scrape</dc:creator><pubDate>Fri, 09 Mar 2007 21:58:28 -0000</pubDate><guid>https://sourceforge.net1c8e24a2fc418aadb7f998cfa23dd16530b4cb88</guid></item></channel></rss>