Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) to_group parameter to group.php or (2) id parameter to vcard.php. NOTE: the edit.php vector is already covered by CVE-2008-2565.
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php_address_book | Chatelao | * | 6.2.11 (including) |
Php_address_book | Chatelao | 1.0 (including) | 1.0 (including) |
Php_address_book | Chatelao | 1.2 (including) | 1.2 (including) |
Php_address_book | Chatelao | 2.0 (including) | 2.0 (including) |
Php_address_book | Chatelao | 2.1 (including) | 2.1 (including) |
Php_address_book | Chatelao | 2.1.1 (including) | 2.1.1 (including) |
Php_address_book | Chatelao | 2.2 (including) | 2.2 (including) |
Php_address_book | Chatelao | 2.3 (including) | 2.3 (including) |
Php_address_book | Chatelao | 2.4 (including) | 2.4 (including) |
Php_address_book | Chatelao | 2.6 (including) | 2.6 (including) |
Php_address_book | Chatelao | 3.0 (including) | 3.0 (including) |
Php_address_book | Chatelao | 3.1 (including) | 3.1 (including) |
Php_address_book | Chatelao | 3.1.1 (including) | 3.1.1 (including) |
Php_address_book | Chatelao | 3.1.2 (including) | 3.1.2 (including) |
Php_address_book | Chatelao | 3.1.3 (including) | 3.1.3 (including) |
Php_address_book | Chatelao | 3.1.4 (including) | 3.1.4 (including) |
Php_address_book | Chatelao | 3.1.5 (including) | 3.1.5 (including) |
Php_address_book | Chatelao | 3.1.6 (including) | 3.1.6 (including) |
Php_address_book | Chatelao | 3.2 (including) | 3.2 (including) |
Php_address_book | Chatelao | 3.2.1 (including) | 3.2.1 (including) |
Php_address_book | Chatelao | 3.2.2 (including) | 3.2.2 (including) |
Php_address_book | Chatelao | 3.2.3 (including) | 3.2.3 (including) |
Php_address_book | Chatelao | 3.2.4 (including) | 3.2.4 (including) |
Php_address_book | Chatelao | 3.2.5 (including) | 3.2.5 (including) |
Php_address_book | Chatelao | 3.2.6 (including) | 3.2.6 (including) |
Php_address_book | Chatelao | 3.2.7 (including) | 3.2.7 (including) |
Php_address_book | Chatelao | 3.2.8 (including) | 3.2.8 (including) |
Php_address_book | Chatelao | 3.2.9 (including) | 3.2.9 (including) |
Php_address_book | Chatelao | 3.2.10 (including) | 3.2.10 (including) |
Php_address_book | Chatelao | 3.2.11 (including) | 3.2.11 (including) |
Php_address_book | Chatelao | 3.2.12 (including) | 3.2.12 (including) |
Php_address_book | Chatelao | 3.2.13 (including) | 3.2.13 (including) |
Php_address_book | Chatelao | 3.2.14 (including) | 3.2.14 (including) |
Php_address_book | Chatelao | 3.3 (including) | 3.3 (including) |
Php_address_book | Chatelao | 3.3.1 (including) | 3.3.1 (including) |
Php_address_book | Chatelao | 3.3.2 (including) | 3.3.2 (including) |
Php_address_book | Chatelao | 3.3.3 (including) | 3.3.3 (including) |
Php_address_book | Chatelao | 3.3.4 (including) | 3.3.4 (including) |
Php_address_book | Chatelao | 3.3.5 (including) | 3.3.5 (including) |
Php_address_book | Chatelao | 3.3.6 (including) | 3.3.6 (including) |
Php_address_book | Chatelao | 3.3.7 (including) | 3.3.7 (including) |
Php_address_book | Chatelao | 3.3.8 (including) | 3.3.8 (including) |
Php_address_book | Chatelao | 3.3.9 (including) | 3.3.9 (including) |
Php_address_book | Chatelao | 3.3.10 (including) | 3.3.10 (including) |
Php_address_book | Chatelao | 3.3.12 (including) | 3.3.12 (including) |
Php_address_book | Chatelao | 3.3.13 (including) | 3.3.13 (including) |
Php_address_book | Chatelao | 3.3.14 (including) | 3.3.14 (including) |
Php_address_book | Chatelao | 3.3.15 (including) | 3.3.15 (including) |
Php_address_book | Chatelao | 3.3.16 (including) | 3.3.16 (including) |
Php_address_book | Chatelao | 3.3.17 (including) | 3.3.17 (including) |
Php_address_book | Chatelao | 3.3.18 (including) | 3.3.18 (including) |
Php_address_book | Chatelao | 3.4 (including) | 3.4 (including) |
Php_address_book | Chatelao | 3.4.1 (including) | 3.4.1 (including) |
Php_address_book | Chatelao | 3.4.2 (including) | 3.4.2 (including) |
Php_address_book | Chatelao | 3.4.3 (including) | 3.4.3 (including) |
Php_address_book | Chatelao | 3.4.4 (including) | 3.4.4 (including) |
Php_address_book | Chatelao | 3.4.5 (including) | 3.4.5 (including) |
Php_address_book | Chatelao | 3.4.6 (including) | 3.4.6 (including) |
Php_address_book | Chatelao | 3.4.7 (including) | 3.4.7 (including) |
Php_address_book | Chatelao | 3.4.8 (including) | 3.4.8 (including) |
Php_address_book | Chatelao | 3.4.9 (including) | 3.4.9 (including) |
Php_address_book | Chatelao | 4.0 (including) | 4.0 (including) |
Php_address_book | Chatelao | 4.0.2 (including) | 4.0.2 (including) |
Php_address_book | Chatelao | 4.1.1 (including) | 4.1.1 (including) |
Php_address_book | Chatelao | 4.1.3 (including) | 4.1.3 (including) |
Php_address_book | Chatelao | 4.1.4 (including) | 4.1.4 (including) |
Php_address_book | Chatelao | 5.0 (including) | 5.0 (including) |
Php_address_book | Chatelao | 5.0-beta (including) | 5.0-beta (including) |
Php_address_book | Chatelao | 5.1 (including) | 5.1 (including) |
Php_address_book | Chatelao | 5.2 (including) | 5.2 (including) |
Php_address_book | Chatelao | 5.3 (including) | 5.3 (including) |
Php_address_book | Chatelao | 5.4 (including) | 5.4 (including) |
Php_address_book | Chatelao | 5.4.1 (including) | 5.4.1 (including) |
Php_address_book | Chatelao | 5.4.2 (including) | 5.4.2 (including) |
Php_address_book | Chatelao | 5.4.3 (including) | 5.4.3 (including) |
Php_address_book | Chatelao | 5.4.4 (including) | 5.4.4 (including) |
Php_address_book | Chatelao | 5.4.5 (including) | 5.4.5 (including) |
Php_address_book | Chatelao | 5.4.6 (including) | 5.4.6 (including) |
Php_address_book | Chatelao | 5.4.7 (including) | 5.4.7 (including) |
Php_address_book | Chatelao | 5.4.9 (including) | 5.4.9 (including) |
Php_address_book | Chatelao | 5.5 (including) | 5.5 (including) |
Php_address_book | Chatelao | 5.6 (including) | 5.6 (including) |
Php_address_book | Chatelao | 5.7 (including) | 5.7 (including) |
Php_address_book | Chatelao | 5.7.1 (including) | 5.7.1 (including) |
Php_address_book | Chatelao | 5.7.2 (including) | 5.7.2 (including) |
Php_address_book | Chatelao | 5.7.3 (including) | 5.7.3 (including) |
Php_address_book | Chatelao | 5.7.4 (including) | 5.7.4 (including) |
Php_address_book | Chatelao | 5.7.5 (including) | 5.7.5 (including) |
Php_address_book | Chatelao | 5.8.1 (including) | 5.8.1 (including) |
Php_address_book | Chatelao | 6.0 (including) | 6.0 (including) |
Php_address_book | Chatelao | 6.1 (including) | 6.1 (including) |
Php_address_book | Chatelao | 6.1.1 (including) | 6.1.1 (including) |
Php_address_book | Chatelao | 6.1.2 (including) | 6.1.2 (including) |
Php_address_book | Chatelao | 6.1.3 (including) | 6.1.3 (including) |
Php_address_book | Chatelao | 6.1.4 (including) | 6.1.4 (including) |
Php_address_book | Chatelao | 6.2 (including) | 6.2 (including) |
Php_address_book | Chatelao | 6.2.1 (including) | 6.2.1 (including) |
Php_address_book | Chatelao | 6.2.2 (including) | 6.2.2 (including) |
Php_address_book | Chatelao | 6.2.3 (including) | 6.2.3 (including) |
Php_address_book | Chatelao | 6.2.4 (including) | 6.2.4 (including) |
Php_address_book | Chatelao | 6.2.5 (including) | 6.2.5 (including) |
Php_address_book | Chatelao | 6.2.6 (including) | 6.2.6 (including) |
Php_address_book | Chatelao | 6.2.7 (including) | 6.2.7 (including) |
Php_address_book | Chatelao | 6.2.9 (including) | 6.2.9 (including) |
Php_address_book | Chatelao | 6.2.10 (including) | 6.2.10 (including) |