CVE-2013-0135

Chatelao Php Address Book - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) addressbook/register/edit_user_save.php; the email parameter to (4) addressbook/register/edit_user_save.php, (5) addressbook/register/reset_password.php, (6) addressbook/register/reset_password_save.php, or (7) addressbook/register/user_add_save.php; the username parameter to (8) addressbook/register/checklogin.php or (9) addressbook/register/reset_password_save.php; the (10) lastname, (11) firstname, (12) phone, (13) permissions, or (14) notes parameter to addressbook/register/edit_user_save.php; the (15) q parameter to addressbook/register/admin_index.php; the (16) site parameter to addressbook/register/linktick.php; the (17) password parameter to addressbook/register/reset_password.php; the (18) password_hint parameter to addressbook/register/reset_password_save.php; the (19) var parameter to addressbook/register/traffic.php; or a (20) BasicLogin cookie to addressbook/register/router.php.

Exploits (11)

exploitdb WRITEUP VERIFIED
by Jurgen Voorneveld · textwebappsphp
https://www.exploit-db.com/exploits/38433
exploitdb WRITEUP VERIFIED
by Jurgen Voorneveld · textwebappsphp
https://www.exploit-db.com/exploits/38432
exploitdb WRITEUP VERIFIED
by Jurgen Voorneveld · textwebappsphp
https://www.exploit-db.com/exploits/38431
exploitdb WRITEUP VERIFIED
by Jurgen Voorneveld · textwebappsphp
https://www.exploit-db.com/exploits/38430
exploitdb WRITEUP VERIFIED
by Jurgen Voorneveld · textwebappsphp
https://www.exploit-db.com/exploits/38429
exploitdb WRITEUP VERIFIED
by Jurgen Voorneveld · textwebappsphp
https://www.exploit-db.com/exploits/38428
exploitdb WRITEUP VERIFIED
by Jurgen Voorneveld · textwebappsphp
https://www.exploit-db.com/exploits/38427
exploitdb WRITEUP VERIFIED
by Jurgen Voorneveld · textwebappsphp
https://www.exploit-db.com/exploits/38426
exploitdb WRITEUP VERIFIED
by Jurgen Voorneveld · textwebappsphp
https://www.exploit-db.com/exploits/38425
exploitdb WRITEUP VERIFIED
by Jurgen Voorneveld · textwebappsphp
https://www.exploit-db.com/exploits/38434
exploitdb WRITEUP VERIFIED
by Jurgen Voorneveld · textwebappsphp
https://www.exploit-db.com/exploits/38435

References (4)

Core 4
Core References
Exploit, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/183692
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99623

Scores

EPSS 0.0346
EPSS Percentile 87.6%

Details

CWE
CWE-89
Status published
Products (1)
chatelao/php_address_book 8.2.5
Published Apr 09, 2013
Tracked Since Feb 18, 2026