6.1
CVSSv3

CVE-2023-4492

Published: 04/10/2023 Updated: 06/10/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate and workzip) of the /addrbook.ghp file, allowing an malicious user to inject a JavaScript payload specially designed to run when the application is loaded

Vulnerable Product Search on Vulmon Subscribe to Product

easy address book web server project easy address book web server 1.6

Exploits

Easy Address Book Web Server version 16 suffers from buffer overflow and cross site scripting vulnerabilities ...