PHP Address Book web application is vulnerable to multiple sqli injection vulnerabilities.
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
PHP Address Book 8.2.5 and possibly older versions fail to sanitize input from multiple functions.
A remote unauthenticated attacker may be able to run a subset of SQL commands against the back-end database.
We are currently unaware of a practical solution to this problem.
Thanks to Jurgen Voorneveld of Acadion Security for reporting this vulnerability.
This document was written by Michael Orlando.
|Date First Published:||2013-04-05|
|Date Last Updated:||2013-04-05 18:00 UTC|