CVE-2009-2608

Loading...

General

Score:6.8/10.0
Severity:Medium
Category:SQL Injection
Exploit:Available

Impact Metrics

Confidentiality:Partial
Integrity:Partial
Availability:Partial

Exploitability Metrics

Access Vector:Network
Access Complexity:Medium
Authentication:None

Published on 27/07/09 - Updated on 10/10/18

Description

Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php. NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565.

Category: SQL Injection

CWE-89 (SQL Injection)
The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.

Security Notices

US National Vulnerability DatabaseCVE-2009-2608

Exploits

Exploit-DBEDB-9023
SecurityFocusBID-35511

Relative technologies

VendorProduct
chatelaophp_address_book

Share this vulnerability with:

Twitter Facebook LinkedIn Mail