CVE Database
/

CVE-2006-2719

Back to search

CVE-2006-2719

Published: Jun 1, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

JIWA Financials 6.4.14 stores usernames and passwords for all accounts in cleartext in the HR_Staff table in Microsoft SQL Server, and sends the usernames and passwords in cleartext to the application's SQL Server ODBC driver, which might allow context-dependent attackers to obtain the passwords.

VendorProductVersions

n/a

n/a

affected
n/a

References

1016181
vdb-entry
x_refsource_SECTRACK
20342
third-party-advisory
x_refsource_SECUNIA
1000
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now