peter bassill · operator
$ cve CVE-2008-2565 JSON

CVE-2008-2565 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 1.9% (pctl 79)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) edit.php. NOTE: it was later reported that 4.0.x is also affected.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.91% — more likely to be exploited than 79% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2008-06-06
Last modified2026-06-16

Affected (1)

VendorProduct
php-address bookphp-address book

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD