7.5
CVE-2006-4575
- EPSS 2.11%
- Veröffentlicht 31.12.2006 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:29:22
- Quelle PSIRT-CNA@flexerasoftware.com
- CVE-Watchlists
- Unerledigt
Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id, (6) language, (7) defaultLetter, (8) newuserPass, (9) newuserType, (10) newuserEmail parameters in (a) user.php; the (11) goTo and (12) search parameters in (b) search.php; and the (13) groupAddName parameter in (c) save.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
The Address Book ≫ The Address Book Version1.04e
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.11% | 0.794 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://osvdb.org/32568
http://osvdb.org/32569
http://osvdb.org/32570
http://secunia.com/advisories/21694
http://secunia.com/secunia_research/2006-76/advisory/
http://www.securityfocus.com/bid/21870
https://exchange.xforce.ibmcloud.com/vulnerabilities/31238