Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Lawson Financials 8.0, when configured to use a third party relational database, stores usernames and passwords in a world-readable file, which allows local users to read the passwords and log onto the database.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lawson Financials帐户信息全局可访问漏洞
Vulnerability Description
Lawson Financials是一款商业金融计划和跟踪软件,可使用在Unix和Microsoft Windows操作系统下。 Lawson Financials存储用户帐户的文件全局可读写,本地攻击者可以利用这个漏洞访问配置文件而获得用户帐户信息,未授权访问系统。 Lawson Finanical部分默认配置允许未授权用户访问敏感信息。默认情况下,Lawson Finanical敏感信息如用户名和密码存储在全局可读写的答谢数据库文件中"capital <database> file"文本文件中。本地攻
CVSS Information
N/A
Vulnerability Type
N/A