Lucene search

K
cve[email protected]CVE-2008-3840
HistoryAug 27, 2008 - 8:41 p.m.

CVE-2008-3840

2008-08-2720:41:00
CWE-255
web.nvd.nist.gov
30
cve-2008-3840
crafty syntax live help
cslh
password security
mysql
sensitive information

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.1%

Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.

Affected configurations

NVD
Node
craftysyntaxcrafty_syntax_live_helpRange2.14.6
OR
craftysyntaxcrafty_syntax_live_helpMatch1.0
OR
craftysyntaxcrafty_syntax_live_helpMatch1.1
OR
craftysyntaxcrafty_syntax_live_helpMatch1.2
OR
craftysyntaxcrafty_syntax_live_helpMatch1.3
OR
craftysyntaxcrafty_syntax_live_helpMatch1.4
OR
craftysyntaxcrafty_syntax_live_helpMatch1.5
OR
craftysyntaxcrafty_syntax_live_helpMatch1.6
OR
craftysyntaxcrafty_syntax_live_helpMatch1.7
OR
craftysyntaxcrafty_syntax_live_helpMatch2.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.2
OR
craftysyntaxcrafty_syntax_live_helpMatch2.3
OR
craftysyntaxcrafty_syntax_live_helpMatch2.4
OR
craftysyntaxcrafty_syntax_live_helpMatch2.5
OR
craftysyntaxcrafty_syntax_live_helpMatch2.6
OR
craftysyntaxcrafty_syntax_live_helpMatch2.7
OR
craftysyntaxcrafty_syntax_live_helpMatch2.7.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.7.2
OR
craftysyntaxcrafty_syntax_live_helpMatch2.7.3
OR
craftysyntaxcrafty_syntax_live_helpMatch2.7.4
OR
craftysyntaxcrafty_syntax_live_helpMatch2.8.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.8.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.8.2
OR
craftysyntaxcrafty_syntax_live_helpMatch2.8.3
OR
craftysyntaxcrafty_syntax_live_helpMatch2.8.4
OR
craftysyntaxcrafty_syntax_live_helpMatch2.9.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.9.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.9.2
OR
craftysyntaxcrafty_syntax_live_helpMatch2.9.3
OR
craftysyntaxcrafty_syntax_live_helpMatch2.9.4
OR
craftysyntaxcrafty_syntax_live_helpMatch2.9.5
OR
craftysyntaxcrafty_syntax_live_helpMatch2.9.6
OR
craftysyntaxcrafty_syntax_live_helpMatch2.9.7
OR
craftysyntaxcrafty_syntax_live_helpMatch2.9.8
OR
craftysyntaxcrafty_syntax_live_helpMatch2.10.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.10.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.10.2
OR
craftysyntaxcrafty_syntax_live_helpMatch2.10.3
OR
craftysyntaxcrafty_syntax_live_helpMatch2.10.4
OR
craftysyntaxcrafty_syntax_live_helpMatch2.10.5
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.2
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.3
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.4
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.5
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.6
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.7
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.2
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.3
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.4
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.5
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.6
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.7
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.8
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.9
OR
craftysyntaxcrafty_syntax_live_helpMatch2.13.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.13.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.14.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.14.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.14.2
OR
craftysyntaxcrafty_syntax_live_helpMatch2.14.3
OR
craftysyntaxcrafty_syntax_live_helpMatch2.14.4
OR
craftysyntaxcrafty_syntax_live_helpMatch2.14.5

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.1%

Related for CVE-2008-3840