PT-2008-5183 · Cslh · Crafty Syntax Live Help
Published
2008-08-27
·
Updated
2018-10-11
·
CVE-2008-3840
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Crafty Syntax Live Help (CSLH) versions 2.14.6 and earlier
Description
The issue allows context-dependent attackers to obtain sensitive information because passwords are stored in cleartext in a MySQL database.
Recommendations
For versions 2.14.6 and earlier, update to a version that securely stores passwords, or consider implementing an alternative password storage solution that does not store passwords in cleartext.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crafty Syntax Live Help