CVE-2008-3763
21.08.2008, 17:41
Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is enabled, allows remote attackers to overwrite arbitrary variables related to the db config file. NOTE: this can be leveraged for code injection by overwriting the language file.Enginsight
Vendor | Product | Version |
---|---|---|
turnkeywebtools | php_live_helper | 𝑥 ≤ 2.0.1 |
turnkeywebtools | php_live_helper | 2.0 |
turnkeywebtools | php_live_helper | 2.0:beta_1 |
turnkeywebtools | php_live_helper | 2.0:beta_2 |
turnkeywebtools | php_live_helper | 2.0:beta_3 |
turnkeywebtools | php_live_helper | 2.0:beta_4 |
turnkeywebtools | php_live_helper | 2.0:beta_5 |
turnkeywebtools | php_live_helper | 2.0:beta_6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References