Multiple SQL injection vulnerabilities in the authentication process in katzlbt (a) The Address Book 1.04e and previous versions and (b) The Address Book Reloaded prior to 2.0-rc4 allow remote malicious users to execute arbitrary SQL commands via the (1) username or (2) password parameters. NOTE: portions of these details are obtained from third party information.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
the address book the address book |
||
the address book reloaded the address book reloaded |