VulnerabilityModified
CVE-2009-2608
Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php.
MEDIUM 6.8EPSS 0.91%
Does this matter?
Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php. NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- chatelao/php address book
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/35590Vendor Advisory
- http://www.exploit-db.com/exploits/9023
- http://www.securityfocus.com/archive/1/504595/100/0/threaded
- http://www.securityfocus.com/bid/35511Exploit
- http://secunia.com/advisories/35590Vendor Advisory
- http://www.exploit-db.com/exploits/9023
- http://www.securityfocus.com/archive/1/504595/100/0/threaded
- http://www.securityfocus.com/bid/35511Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.