Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-3845 (crafty_syntax_live_help)

BugsAlert Home > CVE-2008-3845 (crafty_syntax_live_help)
 
 

Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to execute arbitrary SQL commands via the department parameter to (1) is_xmlhttp.php and (2) is_flush.php.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3845

Learn more about CVE-2008-3845 (crafty_syntax_live_help)
 
Tags: cve-2008-3845 crafty syntax live

Related Items

      Spam evolution: July ? September 2007

      CVE-2007-6609 (CoolPlayer)

      A Growing SoPHISHtication

      WORM_ONLINEG.LYX

      Symantec Mail Security Lotus 1-2-3 File Viewer Buffer Overflows

      Bugtraq: TotalPlayer 3.0 .m3u crash

      Vuln: RealNetworks RealPlayer SWF File Heap Based Buffer Overflow Vulnerability

 

Pixel