Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3845. PoCs published by GulfTech Security.
AI-analyzed exploit summary This is a writeup describing a SQL injection vulnerability in Crafty Syntax Live Help <= 2.14.6. The vulnerability allows an attacker to read arbitrary database contents, including user credentials, by exploiting the 'department' parameter in is_xmlhttp.php or is_flush.php.
Description
Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to execute arbitrary SQL commands via the department parameter to (1) is_xmlhttp.php and (2) is_flush.php.
Exploits (1)
This is a writeup describing a SQL injection vulnerability in Crafty Syntax Live Help <= 2.14.6. The vulnerability allows an attacker to read arbitrary database contents, including user credentials, by exploiting the 'department' parameter in is_xmlhttp.php or is_flush.php.