The Address Book

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 9
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2006-4575

    Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id, (6) language, (7) defaultLetter, (8) newuserPass, (9) newuserType, (10) newuserEmail parameters in (a) user.php; the (11) goTo and (12) search parameters in (b) search.php; and the (13) groupAddName parameter in (c) save.php.

    Last Modified: Apr 23, 2026
    Published: Dec 31, 2006

    CVE-2006-4577

    Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) email, (2) websites, and (3) groupAddName parameters in (a) save.php; the (4) errorMsg parameter in (b) index.php; and the (5) goTo and (6) search parameters in (c) search.php.

    Last Modified: Apr 23, 2026
    Published: Dec 31, 2006

    CVE-2006-4578

    export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote attackers to obtain sensitive information.

    Last Modified: Apr 23, 2026
    Published: Dec 31, 2006

    CVE-2006-4582

    Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote attackers to perform unauthorized actions as other users via unspecified vectors, as demonstrated by deleting arbitrary users via the id parameter in a deleteuser action in users.php.

    Last Modified: Apr 23, 2026
    Published: Dec 31, 2006

    CVE-2006-4581

    Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts.

    Last Modified: Apr 23, 2026
    Published: Dec 31, 2006
    Items Per Page
    The_Address_Book Vulnerabilities & Security CVEs | CVE-DB