Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
References
Configurations
Information
Published : 2010-03-15 06:28
Updated : 2018-10-10 12:51
NVD link : CVE-2010-0124
Mitre link : CVE-2010-0124
JSON object : View
CWE
CWE-255
Credentials Management Errors
Products Affected
timeclock-software
- employee_timeclock_software