Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Very High

CVE-2020-8510

Disclosure Date: February 03, 2020 (last updated February 21, 2025)
An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.
Attacker Value
Unknown

CVE-2022-30352

Disclosure Date: June 02, 2022 (last updated October 07, 2023)
phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script.