Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/509996/100/0/threaded | mailing list |
http://secunia.com/advisories/38739 | third party advisory vendor advisory |
http://secunia.com/secunia_research/2010-12/ | vendor advisory |
http://www.osvdb.org/62830 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/56800 | vdb entry |
http://www.securityfocus.com/bid/38642 | vdb entry |