Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
https://exchange.xforce.ibmcloud.com/vulnerabilities/56800
http://www.securityfocus.com/bid/38642
http://www.securityfocus.com/archive/1/509996/100/0/threaded