CVE-2008-7145

Coronamatrix Phpaddressbook - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in index.php in CoronaMatrix phpAddressBook 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Virangar Security · textwebappsphp
https://www.exploit-db.com/exploits/31539

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28456
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/490097/100/0/threaded
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/51050

Scores

EPSS 0.0011
EPSS Percentile 28.6%

Details

CWE
CWE-89
Status published
Products (1)
coronamatrix/phpaddressbook 2.0
Published Sep 01, 2009
Tracked Since Feb 18, 2026