CVE-2010-0123

Publication date

2010-03-12 20:00:00

Family

flexera

State

PUBLISHED

Description

The database backup implementation in Employee Timeclock Software 0.99 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a "semi-predictable file name."