Total vulnerabilities in the database
Multiple SQL injection vulnerabilities in the authentication process in katzlbt (a) The Address Book 1.04e and earlier and (b) The Address Book Reloaded before 2.0-rc4 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. NOTE: portions of these details are obtained from third party information.
Software | From | Fixed in |
---|---|---|
the_address_book / the_address_book | - | 1.04e.x |
the_address_book_reloaded / the_address_book_reloaded | - | 2.0.x |