Skip to main content

Vendor/product archive

the_address_book / the_address_book CVEs

Beta · best-effort

9 CVEs tagged to the_address_book / the_address_book0 Critical, 4 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2006-4575

Published Dec 31, 2006

Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4576

Published Dec 31, 2006

Cross-site scripting (XSS) vulnerability in The Address Book 1.04e allows remote attackers to inject arbitrary web script or HTML by uploading the HTML file with a GIF or JPG exte…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4577

Published Dec 31, 2006

Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) email,…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4578

Published Dec 31, 2006

export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote at…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4579

Published Dec 31, 2006

Directory traversal vulnerability in users.php in The Address Book 1.04e allows remote attackers to include arbitrary files via a .. (dot dot) in the language parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4580

Published Dec 31, 2006

register.php in The Address Book 1.04e allows remote attackers to bypass the "Allow User Self-Registration" setting and create arbitrary users by setting the mode parameter to "co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4581

Published Dec 31, 2006

Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PH…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4582

Published Dec 31, 2006

Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote attackers to perform unauthorized actions as other users via unspecified vectors, as demons…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1