← volver
CVE-2020-37083

addressbook 9.0.0.1 - 'id' SQL Injection

CVSS 8.8 HIGHEPSS 0.3%CWE-89
PHP AddressBook 9.0.0.1 contains a time-based blind SQL injection vulnerability that allows remote attackers to manipulate database queries through the 'id' parameter. Attackers can inject crafted SQL statements with time delays to extract information by observing response times in the photo.php endpoint.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
chatelao · PHP Address Book

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →