functional security
Showing 1 - 1 of 1 RSS Feed

Files

Employee Timeclock Software mysqldump Password Disclosure
Posted Mar 10, 2010
Site secunia.com

Secunia Research has discovered security issue in Employee Timeclock Software, which can be exploited by malicious, local users to disclose sensitive information. The security issue is caused due to the application passing the database password via the command line to the "mysqldump" utility, which potentially can be exploited to disclose the password via the process list. Version 0.99 is affected.

tags | advisory, local, info disclosure
advisories | CVE-2010-0124
MD5 | 5c55f50ca9c91dbe8978a3bb60746a6c
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close