VulnerabilityModified
CVE-2008-2566
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI.
MEDIUM 4.3EPSS 1.53%
Does this matter?
Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- php-address book/php-address book
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/129789/PHP-Address-Book-Cross-Site-Scripting-SQL-Injection.htmlExploit
- http://secunia.com/advisories/30540Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42856
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99624
- https://www.exploit-db.com/exploits/5739
- http://packetstormsecurity.com/files/129789/PHP-Address-Book-Cross-Site-Scripting-SQL-Injection.htmlExploit
- http://secunia.com/advisories/30540Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42856
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99624
- https://www.exploit-db.com/exploits/5739
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.