Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2006-1050 | First vendor Publication | 2006-03-07 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 2.1 | Attack Range | Local |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Kwik-Pay Payroll 4.2.20, and possibly other versions, stores the KwikPay.mdb database file with insecure permissions, which allows local users to obtain sensitive information such as employment and payment data. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: the vendor has disputed this vulnerability, stating that "The kwikpay.mdb file supplied with kwikpay is a template for the database structure of user databases created by kwikpay and to store a demonstration payroll. It does not contain any sensitive user information. When a user payroll database is opened, the encryption of the database is checked and if the database is not encrypted, the user is prompted to encrypt the database, but the choice is the customers. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1050 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
23617 | Kwik-Pay Payroll Payroll and Employment Information Disclosure Kwik-Pay Payroll contains a flaw that may lead to an unauthorized information disclosure. The issue is due to employment and payment information being stored in database files with insecure file permissions in the installation directory, which is accessible by any local user on the system. |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 23:20:58 |
|
2024-11-28 12:08:26 |
|
2024-08-07 21:28:14 |
|
2024-05-17 09:28:45 |
|
2024-05-14 21:28:31 |
|
2024-04-11 09:28:48 |
|
2024-03-21 09:28:50 |
|
2023-11-07 21:48:05 |
|
2021-05-04 12:03:45 |
|
2021-04-22 01:04:18 |
|
2020-05-23 00:17:29 |
|
2017-07-20 09:23:24 |
|
2016-06-28 15:39:03 |
|
2016-04-26 14:22:13 |
|
2013-05-11 10:50:54 |
|