Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2024-51644
Disclosure Date: November 19, 2024 (last updated November 20, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Sam Wilson Addressbook allows Stored XSS.This issue affects Addressbook: from n/a through 1.1.3.
0
Attacker Value
Unknown
CVE-2012-2307
Disclosure Date: July 25, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown
CVE-2010-4990
Disclosure Date: November 01, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the Front-edit Address Book (com_addressbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a contact action to index.php.
0
Attacker Value
Unknown
CVE-2010-1471
Disclosure Date: April 19, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown
CVE-2008-7145
Disclosure Date: September 01, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in CoronaMatrix phpAddressBook 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) parameters.
0
Attacker Value
Unknown
CVE-2008-6646
Disclosure Date: April 07, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in CoronaMatrix phpAddressBook 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
0
Attacker Value
Unknown
CVE-2008-1847
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
SQL injection vulnerability in view.php in CoronaMatrix phpAddressBook 2.11 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2008-1492
Disclosure Date: March 25, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in CoronaMatrix phpAddressBook 2.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php and (2) install.php. NOTE: it was later reported that vector 1 is also present in 2.0.
0
Attacker Value
Unknown
CVE-2007-1720
Disclosure Date: March 28, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file.
0
Attacker Value
Unknown
CVE-2006-4460
Disclosure Date: August 31, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in PHP iAddressBook before 0.96 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0