Lucene search

K
nvd[email protected]NVD:CVE-2008-3845
HistoryAug 27, 2008 - 11:41 p.m.

CVE-2008-3845

2008-08-2723:41:00
CWE-89
web.nvd.nist.gov

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.5 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

65.7%

Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to execute arbitrary SQL commands via the department parameter to (1) is_xmlhttp.php and (2) is_flush.php.

Affected configurations

NVD
Node
craftysyntaxcrafty_syntax_live_helpRange2.14.6
OR
craftysyntaxcrafty_syntax_live_helpMatch1.0
OR
craftysyntaxcrafty_syntax_live_helpMatch1.1
OR
craftysyntaxcrafty_syntax_live_helpMatch1.2
OR
craftysyntaxcrafty_syntax_live_helpMatch1.3
OR
craftysyntaxcrafty_syntax_live_helpMatch1.4
OR
craftysyntaxcrafty_syntax_live_helpMatch1.5
OR
craftysyntaxcrafty_syntax_live_helpMatch1.6
OR
craftysyntaxcrafty_syntax_live_helpMatch1.7
OR
craftysyntaxcrafty_syntax_live_helpMatch2.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.10.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.10.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.10.2
OR
craftysyntaxcrafty_syntax_live_helpMatch2.10.3
OR
craftysyntaxcrafty_syntax_live_helpMatch2.10.4
OR
craftysyntaxcrafty_syntax_live_helpMatch2.10.5
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.2
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.3
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.4
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.5
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.6
OR
craftysyntaxcrafty_syntax_live_helpMatch2.11.7
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.2
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.3
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.4
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.5
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.6
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.7
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.8
OR
craftysyntaxcrafty_syntax_live_helpMatch2.12.9
OR
craftysyntaxcrafty_syntax_live_helpMatch2.13.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.13.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.14.0
OR
craftysyntaxcrafty_syntax_live_helpMatch2.14.1
OR
craftysyntaxcrafty_syntax_live_helpMatch2.14.2
OR
craftysyntaxcrafty_syntax_live_helpMatch2.14.3
OR
craftysyntaxcrafty_syntax_live_helpMatch2.14.4
OR
craftysyntaxcrafty_syntax_live_helpMatch2.14.5

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.5 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

65.7%

Related for NVD:CVE-2008-3845