PT-2006-5364 · Unknown · The Address Book
Published
2006-12-31
·
Updated
2017-07-20
·
CVE-2006-4577
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
The Address Book version 1.04e
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via Javascript events in several parameters across different PHP files. The affected parameters include
email, websites, and groupAddName in "save.php", errorMsg in "index.php", and goTo and search in "search.php".Recommendations
For version 1.04e, update to a version that addresses these XSS vulnerabilities to prevent remote attackers from injecting arbitrary web script or HTML. As a temporary workaround, consider restricting user input for the
email, websites, groupAddName, errorMsg, goTo, and search parameters in the respective PHP files until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
The Address Book