Lucene search

K
nvd[email protected]NVD:CVE-2009-2608
HistoryJul 27, 2009 - 6:30 p.m.

CVE-2009-2608

2009-07-2718:30:00
CWE-89
web.nvd.nist.gov
2

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8.2

Confidence

Low

EPSS

0.003

Percentile

70.4%

Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php. NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565.

Affected configurations

Nvd
Node
chatelaophp_address_bookMatch4.0.1
OR
chatelaophp_address_bookMatch4.0.2
VendorProductVersionCPE
chatelaophp_address_book4.0.1cpe:2.3:a:chatelao:php_address_book:4.0.1:*:*:*:*:*:*:*
chatelaophp_address_book4.0.2cpe:2.3:a:chatelao:php_address_book:4.0.2:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8.2

Confidence

Low

EPSS

0.003

Percentile

70.4%

Related for NVD:CVE-2009-2608