PT-2006-5364 · Unknown · The Address Book

Published

2006-12-31

·

Updated

2017-07-20

·

CVE-2006-4577

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions The Address Book version 1.04e
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via Javascript events in several parameters across different PHP files. The affected parameters include email, websites, and groupAddName in "save.php", errorMsg in "index.php", and goTo and search in "search.php".
Recommendations For version 1.04e, update to a version that addresses these XSS vulnerabilities to prevent remote attackers from injecting arbitrary web script or HTML. As a temporary workaround, consider restricting user input for the email, websites, groupAddName, errorMsg, goTo, and search parameters in the respective PHP files until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4577

Affected Products

The Address Book