Show filters
67 Total Results
Displaying 51-60 of 67
Sort by:
Attacker Value
Unknown
CVE-2007-1121
Disclosure Date: February 27, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-1122
Disclosure Date: February 27, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 and 1.01 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php, a variant of a SQL injection issue that was fixed in 1.01. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-4575
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id, (6) language, (7) defaultLetter, (8) newuserPass, (9) newuserType, (10) newuserEmail parameters in (a) user.php; the (11) goTo and (12) search parameters in (b) search.php; and the (13) groupAddName parameter in (c) save.php.
0
Attacker Value
Unknown
CVE-2006-4577
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) email, (2) websites, and (3) groupAddName parameters in (a) save.php; the (4) errorMsg parameter in (b) index.php; and the (5) goTo and (6) search parameters in (c) search.php.
0
Attacker Value
Unknown
CVE-2006-4582
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote attackers to perform unauthorized actions as other users via unspecified vectors, as demonstrated by deleting arbitrary users via the id parameter in a deleteuser action in users.php.
0
Attacker Value
Unknown
CVE-2006-4579
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in users.php in The Address Book 1.04e allows remote attackers to include arbitrary files via a .. (dot dot) in the language parameter.
0
Attacker Value
Unknown
CVE-2006-4581
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts.
0
Attacker Value
Unknown
CVE-2006-4576
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in The Address Book 1.04e allows remote attackers to inject arbitrary web script or HTML by uploading the HTML file with a GIF or JPG extension, which is rendered by Internet Explorer.
0
Attacker Value
Unknown
CVE-2006-4580
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
register.php in The Address Book 1.04e allows remote attackers to bypass the "Allow User Self-Registration" setting and create arbitrary users by setting the mode parameter to "confirm".
0
Attacker Value
Unknown
CVE-2006-4578
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote attackers to obtain sensitive information.
0