CVE-2008-3762
Summary
| CVE | CVE-2008-3762 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-08-21 17:41:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the dep parameter, related to lack of input sanitization in the get function in global.php. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Turnkeywebtools | Php Live Helper | 2.0 | All | All | All |
| Application | Turnkeywebtools | Php Live Helper | 2.0 | beta_1 | All | All |
| Application | Turnkeywebtools | Php Live Helper | 2.0 | beta_2 | All | All |
| Application | Turnkeywebtools | Php Live Helper | 2.0 | beta_3 | All | All |
| Application | Turnkeywebtools | Php Live Helper | 2.0 | beta_4 | All | All |
| Application | Turnkeywebtools | Php Live Helper | 2.0 | beta_5 | All | All |
| Application | Turnkeywebtools | Php Live Helper | 2.0 | beta_6 | All | All |
| Application | Turnkeywebtools | Php Live Helper | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHP Live Helper <= 2.0.1 Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Contact Support | af854a3a-2127-422b-91ae-364da2661108 | www.gulftech.org | Exploit |
| SecurityReason - PHP Live Helper <= 2.0.1 Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| PHP Live Helper Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| PHP Live Helper Multiple Input Validation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.