Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-3840

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2008-3840
Last Modified 29 Jan 2009 01:54:33
Published 27 Aug 2008 04:41:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-3840

Summary

Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.

Vulnerable Systems

Application

  • Craftysyntax Crafty Syntax Live Help 1.0

  • Craftysyntax Crafty Syntax Live Help 1.1

  • Craftysyntax Crafty Syntax Live Help 1.2

  • Craftysyntax Crafty Syntax Live Help 1.3

  • Craftysyntax Crafty Syntax Live Help 1.4

  • Craftysyntax Crafty Syntax Live Help 1.5

  • Craftysyntax Crafty Syntax Live Help 1.6

  • Craftysyntax Crafty Syntax Live Help 1.7

  • Craftysyntax Crafty Syntax Live Help 2.0

  • Craftysyntax Crafty Syntax Live Help 2.1

  • Craftysyntax Crafty Syntax Live Help 2.10.0

  • Craftysyntax Crafty Syntax Live Help 2.10.1

  • Craftysyntax Crafty Syntax Live Help 2.10.2

  • Craftysyntax Crafty Syntax Live Help 2.10.3

  • Craftysyntax Crafty Syntax Live Help 2.10.4

  • Craftysyntax Crafty Syntax Live Help 2.10.5

  • Craftysyntax Crafty Syntax Live Help 2.11.0

  • Craftysyntax Crafty Syntax Live Help 2.11.1

  • Craftysyntax Crafty Syntax Live Help 2.11.2

  • Craftysyntax Crafty Syntax Live Help 2.11.3

  • Craftysyntax Crafty Syntax Live Help 2.11.4

  • Craftysyntax Crafty Syntax Live Help 2.11.5

  • Craftysyntax Crafty Syntax Live Help 2.11.6

  • Craftysyntax Crafty Syntax Live Help 2.11.7

  • Craftysyntax Crafty Syntax Live Help 2.12.0

  • Craftysyntax Crafty Syntax Live Help 2.12.1

  • Craftysyntax Crafty Syntax Live Help 2.12.2

  • Craftysyntax Crafty Syntax Live Help 2.12.3

  • Craftysyntax Crafty Syntax Live Help 2.12.4

  • Craftysyntax Crafty Syntax Live Help 2.12.5

  • Craftysyntax Crafty Syntax Live Help 2.12.6

  • Craftysyntax Crafty Syntax Live Help 2.12.7

  • Craftysyntax Crafty Syntax Live Help 2.12.8

  • Craftysyntax Crafty Syntax Live Help 2.12.9

  • Craftysyntax Crafty Syntax Live Help 2.13.0

  • Craftysyntax Crafty Syntax Live Help 2.13.1

  • Craftysyntax Crafty Syntax Live Help 2.14.0

  • Craftysyntax Crafty Syntax Live Help 2.14.1

  • Craftysyntax Crafty Syntax Live Help 2.14.2

  • Craftysyntax Crafty Syntax Live Help 2.14.3

  • Craftysyntax Crafty Syntax Live Help 2.14.4

  • Craftysyntax Crafty Syntax Live Help 2.14.5

  • Craftysyntax Crafty Syntax Live Help 2.14.6

  • Craftysyntax Crafty Syntax Live Help 2.2

  • Craftysyntax Crafty Syntax Live Help 2.3

  • Craftysyntax Crafty Syntax Live Help 2.4

  • Craftysyntax Crafty Syntax Live Help 2.5

  • Craftysyntax Crafty Syntax Live Help 2.6

  • Craftysyntax Crafty Syntax Live Help 2.7

  • Craftysyntax Crafty Syntax Live Help 2.7.1

  • Craftysyntax Crafty Syntax Live Help 2.7.2

  • Craftysyntax Crafty Syntax Live Help 2.7.3

  • Craftysyntax Crafty Syntax Live Help 2.7.4

  • Craftysyntax Crafty Syntax Live Help 2.8.0

  • Craftysyntax Crafty Syntax Live Help 2.8.1

  • Craftysyntax Crafty Syntax Live Help 2.8.2

  • Craftysyntax Crafty Syntax Live Help 2.8.3

  • Craftysyntax Crafty Syntax Live Help 2.8.4

  • Craftysyntax Crafty Syntax Live Help 2.9.0

  • Craftysyntax Crafty Syntax Live Help 2.9.1

  • Craftysyntax Crafty Syntax Live Help 2.9.2

  • Craftysyntax Crafty Syntax Live Help 2.9.3

  • Craftysyntax Crafty Syntax Live Help 2.9.4

  • Craftysyntax Crafty Syntax Live Help 2.9.5

  • Craftysyntax Crafty Syntax Live Help 2.9.6

  • Craftysyntax Crafty Syntax Live Help 2.9.7

  • Craftysyntax Crafty Syntax Live Help 2.9.8


References

MISC - http://www.gulftech.org/?node=research&article_id=00127-08252008

XF - crafty-syntax-info-disclosure(44745)

BUGTRAQ - 20080825 Crafty Syntax Live Help <= 2.14.6 SQL Injection

SREASON - 4192


Last Updated: 27 May 2016 10:48:19