Record summary

CVE-2020-37083 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

PHP AddressBook 9.0.0.1 contains a time-based blind SQL injection vulnerability that allows remote attackers to manipulate database queries through the 'id' parameter. Attackers can inject crafted SQL statements with time delays to extract information by observing response times in the photo.php endpoint.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List9.0.0.1affected

Proofs of concept

1

Catalogued exploits

ExploitDBaddressbook 9.0.0.1 - 'id' SQL InjectionExploitDB exploitby David VelazquezNot analyzed1 file
ExploitDB

PoC details

References

4