Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
the address book the address book vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2006-4056
Multiple SQL injection vulnerabilities in the authentication process in katzlbt (a) The Address Book 1.04e and previous versions and (b) The Address Book Reloaded prior to 2.0-rc4 allow remote malicious users to execute arbitrary SQL commands via the (1) username or (2) password ...
The Address Book The Address Book
The Address Book Reloaded The Address Book Reloaded
6.8
CVSSv2
CVE-2006-4576
Cross-site scripting (XSS) vulnerability in The Address Book 1.04e allows remote malicious users to inject arbitrary web script or HTML by uploading the HTML file with a GIF or JPG extension, which is rendered by Internet Explorer.
The Address Book The Address Book 1.04e
5
CVSSv2
CVE-2006-4579
Directory traversal vulnerability in users.php in The Address Book 1.04e allows remote malicious users to include arbitrary files via a .. (dot dot) in the language parameter.
The Address Book The Address Book 1.04e
5
CVSSv2
CVE-2006-4581
Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote malicious users to upload arbitrary PHP scripts.
The Address Book The Address Book 1.04e
5
CVSSv2
CVE-2006-4582
Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote malicious users to perform unauthorized actions as other users via unspecified vectors, as demonstrated by deleting arbitrary users via the id parameter in a deleteuser action in users.php.
The Address Book The Address Book 1.04e
7.5
CVSSv2
CVE-2006-4575
Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote malicious users to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id, (6) language, (7) defaultLetter, (8) newuserPass, (9) newuserType, (10) n...
The Address Book The Address Book 1.04e
7.5
CVSSv2
CVE-2006-4578
export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote malicious users to obtain sensitive information.
The Address Book The Address Book 1.04e
6.8
CVSSv2
CVE-2006-4577
Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote malicious users to inject arbitrary web script or HTML via Javascript events in the (1) email, (2) websites, and (3) groupAddName parameters in (a) save.php; the (4) errorMsg parameter in (...
The Address Book The Address Book 1.04e
7.5
CVSSv2
CVE-2006-4580
register.php in The Address Book 1.04e allows remote malicious users to bypass the "Allow User Self-Registration" setting and create arbitrary users by setting the mode parameter to "confirm".
The Address Book The Address Book 1.04e
7.5
CVSSv2
CVE-2008-2565
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and previous versions allow remote malicious users to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) edit.php. NOTE: it was later reported that 4.0.x is also affected.
Php-address Book Php-address Book 3.1.2
Php-address Book Php-address Book 3.1.1
Php-address Book Php-address Book 2.1.1
Php-address Book Php-address Book 2.1
Php-address Book Php-address Book 2.0
Php-address Book Php-address Book 3.4.4
Php-address Book Php-address Book 3.4.3
Php-address Book Php-address Book
Php-address Book Php-address Book 3.1.5
Php-address Book Php-address Book 2.6
Php-address Book Php-address Book 2.4
Php-address Book Php-address Book 3.4.8
Php-address Book Php-address Book 3.4.7
Php-address Book Php-address Book 3.4
Php-address Book Php-address Book 3.3.18
Php-address Book Php-address Book 3.1
Php-address Book Php-address Book 3.0
Php-address Book Php-address Book 1.2
Php-address Book Php-address Book 1.0
Php-address Book Php-address Book 3.4.2
Php-address Book Php-address Book 3.4.1
Php-address Book Php-address Book 3.1.4
3 EDB exploits
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »