Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
References
Configurations
History
21 Nov 2024, 01:11
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/38739 - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2010-12/ - Vendor Advisory | |
References | () http://www.osvdb.org/62830 - | |
References | () http://www.securityfocus.com/archive/1/509996/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/38642 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/56800 - |
Information
Published : 2010-03-15 13:28
Updated : 2024-11-21 01:11
NVD link : CVE-2010-0124
Mitre link : CVE-2010-0124
CVE.ORG link : CVE-2010-0124
JSON object : View
Products Affected
timeclock-software
- employee_timeclock_software
CWE
CWE-255
Credentials Management Errors