Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2024-51644

Disclosure Date: November 19, 2024 (last updated November 20, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Sam Wilson Addressbook allows Stored XSS.This issue affects Addressbook: from n/a through 1.1.3.
0
Attacker Value
Unknown

CVE-2012-2307

Disclosure Date: July 25, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown

CVE-2010-4990

Disclosure Date: November 01, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the Front-edit Address Book (com_addressbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a contact action to index.php.
0
Attacker Value
Unknown

CVE-2010-1471

Disclosure Date: April 19, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown

CVE-2008-7145

Disclosure Date: September 01, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in CoronaMatrix phpAddressBook 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) parameters.
0
Attacker Value
Unknown

CVE-2008-6646

Disclosure Date: April 07, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in CoronaMatrix phpAddressBook 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
0
Attacker Value
Unknown

CVE-2008-1847

Disclosure Date: April 16, 2008 (last updated October 04, 2023)
SQL injection vulnerability in view.php in CoronaMatrix phpAddressBook 2.11 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2008-1492

Disclosure Date: March 25, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in CoronaMatrix phpAddressBook 2.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php and (2) install.php. NOTE: it was later reported that vector 1 is also present in 2.0.
0
Attacker Value
Unknown

CVE-2007-1720

Disclosure Date: March 28, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file.
0
Attacker Value
Unknown

CVE-2006-4460

Disclosure Date: August 31, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in PHP iAddressBook before 0.96 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0