Vulnerabilities > CVE-2008-3840 - Credentials Management vulnerability in Craftysyntax Crafty Syntax Live Help
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- http://securityreason.com/securityalert/4192
- http://securityreason.com/securityalert/4192
- http://www.gulftech.org/?node=research&article_id=00127-08252008
- http://www.gulftech.org/?node=research&article_id=00127-08252008
- http://www.securityfocus.com/archive/1/495729/100/0/threaded
- http://www.securityfocus.com/archive/1/495729/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44745
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44745