The-address-book
8 CVEs tracked since 2007. Since Jan 2007, none of them reached CISA KEV.
The-address-book CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2007-01 | 8 | 0 |
Products
The products that kept showing up in The-address-book's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 9 most recently published vulnerabilities affecting The-address-book.
- CVE-2006-4579Directory traversal vulnerability in users.php in The Address Book 1.04e allows remote attackers to include arbitrary files via a .. (dot dot) in the language parameter.5.0
- CVE-2006-4578export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote attackers to obtain ...7.5
- CVE-2006-4582Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote attackers to perform unauthorized actions as other users via unspecified vectors, as demonstrated by deleting...5.0
- CVE-2006-4575Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) ...7.5
- CVE-2006-4576Cross-site scripting (XSS) vulnerability in The Address Book 1.04e allows remote attackers to inject arbitrary web script or HTML by uploading the HTML file with a GIF or JPG extension, which is re...6.8
- CVE-2006-4581Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts.5.0
- CVE-2006-4580register.php in The Address Book 1.04e allows remote attackers to bypass the "Allow User Self-Registration" setting and create arbitrary users by setting the mode parameter to "confirm".7.5
- CVE-2006-4577Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) email, (2) websites, and...6.8
- CVE-2006-4056Multiple SQL injection vulnerabilities in the authentication process in katzlbt (a) The Address Book 1.04e and earlier and (b) The Address Book Reloaded before 2.0-rc4 allow remote attackers to exe...7.5
The record
- Peak rank
- #12 in Jan 2007
- Busiest month shown
- Jan 2007, 8 CVEs
- Months with a KEV entry
- 0 since Jan 2007
- Monthly snapshots
- 1 since 2007