CVE-2013-0135
23Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendepss 3.0%
de la publicación al arma0 días
Publicada en NVD9 abr
1ª PoC5 abr
probabilidad de explotación
3.0%top 14% de las CVE
explotación observada
noninguna fuente lo reporta
12 exploit(s) público(s)
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) addressbook/register/edit_user_save.php; the email parameter to (4) addressbook/register/edit_user_save.php, (5) addressbook/register/reset_password.php, (6) addressbook/register/reset_password_save.php, or (7) addressbook/register/user_add_save.php; the username parameter to (8) addressbook/register/checklogin.php or (9) addressbook/register/reset_password_save.php; the (10) lastname, (11) firstname, (12) phone, (13) permissions, or (14) notes parameter to addressbook/register/edit_user_save.php; the (15) q parameter to addressbook/register/admin_index.php; the (16) site parameter to addressbook/register/linktick.php; the (17) password parameter to addressbook/register/reset_password.php; the (18) password_hint parameter to addressbook/register/reset_password_save.php; the (19) var parameter to addressbook/register/traffic.php; or a (20) BasicLogin cookie to addressbook/register/router.php.
Productos afectados
n/a · n/aPoCs públicas encontradas — 12✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38433exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38435exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38434exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38425exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38426exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38427exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38428exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38429exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38430exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38431exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38432cve_referencepacketstormsecurity.com/files/129789/PHP-Address-Book-Cross-Site-Scripting-SQL-Injection.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.