CVE-2008-3762

SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the dep parameter, related to lack of input sanitization in the get function in global.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
VendorProductVersion
turnkeywebtoolsphp_live_helper
𝑥
≤ 2.0.1
turnkeywebtoolsphp_live_helper
2.0
turnkeywebtoolsphp_live_helper
2.0:beta_1
turnkeywebtoolsphp_live_helper
2.0:beta_2
turnkeywebtoolsphp_live_helper
2.0:beta_3
turnkeywebtoolsphp_live_helper
2.0:beta_4
turnkeywebtoolsphp_live_helper
2.0:beta_5
turnkeywebtoolsphp_live_helper
2.0:beta_6
𝑥
= Vulnerable software versions