nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37083 CVE-2020-37083
HIGH
addressbook 9.0.0.1 - 'id' SQL Injection
Record summary
CVE-2020-37083 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
PHP AddressBook 9.0.0.1 contains a time-based blind SQL injection vulnerability that allows remote attackers to manipulate database queries through the 'id' parameter. Attackers can inject crafted SQL statements with time delays to extract information by observing response times in the photo.php endpoint.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PHP Address BookBrowse chatelao / PHP Address Book | CVE List | 9.0.0.1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBaddressbook 9.0.0.1 - 'id' SQL InjectionExploitDB exploitby David VelazquezNot analyzed1 file
References
4SourceForge Product Pageproduct
https://sourceforge.net/projects/php-addressbook ExploitDB-48416exploit
https://www.exploit-db.com/exploits/48416 VulnCheck Advisory: addressbook 9.0.0.1 - 'id' SQL InjectionThird-party advisory
https://www.vulncheck.com/advisories/addressbook-id-sql-injection