5
CVSSv2

CVE-2006-4581

Published: 31/12/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote malicious users to upload arbitrary PHP scripts.

Vulnerable Product Search on Vulmon Subscribe to Product

the address book the address book 1.04e