CVE-2013-1748

Chatelao Php Address Book - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) edit.php or (2) import.php. NOTE: the view.php id vector is already covered by CVE-2008-2565.1 and the edit.php id vector is already covered by CVE-2008-2565.2.

Exploits (1)

exploitdb WORKING POC VERIFIED
by CWH Underground · textwebappsphp
https://www.exploit-db.com/exploits/5739

References (2)

Core 2
Core References
Exploit mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2013/04/17/2
Exploit mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2013/04/17/5

Scores

EPSS 0.0036
EPSS Percentile 58.3%

Details

CWE
CWE-89
Status published
Products (1)
chatelao/php_address_book 8.2.5
Published Apr 18, 2013
Tracked Since Feb 18, 2026