CVE-2009-2259 (php-address_book) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2009-2259 (php-address_book)


Heap
01-07-09, 02:50
Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via (1) the alphabet parameter to index.php or (2) the id parameter to delete.php. NOTE: the view.php and edit.php vectors are already covered by CVE-2008-2565.

More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-2259)