CVE-2008-3845 | Craftysyntax Crafty Syntax Live Help up to 1.7 is_xmlhttp.php department sql injection (EDB-6307 / XFDB-44669)
A vulnerability, which was classified as critical, was found in Craftysyntax Crafty Syntax Live Help up to 1.7. Affected is an unknown function of the file is_xmlhttp.php of the component Help. The manipulation of the argument department leads to sql injection.
This vulnerability is traded as CVE-2008-3845. It is possible to launch the attack remotely. Furthermore, there is an exploit available.