Show filters
67 Total Results
Displaying 41-50 of 67
Sort by:
Attacker Value
Unknown

CVE-2010-1058

Disclosure Date: March 23, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter.
0
Attacker Value
Unknown

CVE-2009-2608

Disclosure Date: July 27, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php. NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565.
0
Attacker Value
Unknown

CVE-2009-1483

Disclosure Date: April 29, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable from index2.php, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in profiles/.
0
Attacker Value
Unknown

CVE-2008-6458

Disclosure Date: March 13, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the FE address edit for tt_address & direct mail (dmaddredit) extension 0.4.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-3038

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the Address Directory (sp_directory) extension 0.2.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-3037

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Address Directory (sp_directory) extension 0.2.10 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-2566

Disclosure Date: June 06, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI.
0
Attacker Value
Unknown

CVE-2008-2565

Disclosure Date: June 06, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) edit.php. NOTE: it was later reported that 4.0.x is also affected.
0
Attacker Value
Unknown

CVE-2007-4179

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors. NOTE: this is probably different from CVE-2007-0916, but this is not certain due to lack of vendor details.
0
Attacker Value
Unknown

CVE-2007-1596

Disclosure Date: March 22, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) components/com_nfn_addressbook/nfnaddressbook.php or (2) administrator/components/com_nfn_addressbook/nfnaddressbook.php.
0