← Back

CVE-2012-1911

nvd nist
Published: Sep 9, 2012Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) to_group parameter to group.php or (2) id parameter to vcard.php. NOTE: the edit.php vector is already covered by CVE-2008-2565.

Affected (105)

1 product
Php Address Book
Configuration A
105 vulnerable
Vulnerable SoftwareAffected Versions
Chatelao
Up to 6.2.11
Version 1.0
Version 1.2
Version 2.0
Version 2.1.1
Version 2.1
Version 2.2
Version 2.3
Version 2.4
Version 2.6
Version 3.0
Version 3.1.1
Version 3.1.2
Version 3.1.3
Version 3.1.4
Version 3.1.5
Version 3.1.6
Version 3.1
Version 3.2.10
Version 3.2.11
Version 3.2.12
Version 3.2.13
Version 3.2.14
Version 3.2.1
Version 3.2.2
Version 3.2.3
Version 3.2.4
Version 3.2.5
Version 3.2.6
Version 3.2.7
Version 3.2.8
Version 3.2.9
Version 3.2
Version 3.3.10
Version 3.3.12
Version 3.3.13
Version 3.3.14
Version 3.3.15
Version 3.3.16
Version 3.3.17
Version 3.3.18
Version 3.3.1
Version 3.3.2
Version 3.3.3
Version 3.3.4
Version 3.3.5
Version 3.3.6
Version 3.3.7
Version 3.3.8
Version 3.3.9
Version 3.3
Version 3.4.1
Version 3.4.2
Version 3.4.3
Version 3.4.4
Version 3.4.5
Version 3.4.6
Version 3.4.7
Version 3.4.8
Version 3.4.9
Version 3.4
Version 4.0.2
Version 4.0
Version 4.1.1
Version 4.1.3
Version 4.1.4
Version 5.0
Version 5.0 beta
Version 5.1
Version 5.2
Version 5.3
Version 5.4.1
Version 5.4.2
Version 5.4.3
Version 5.4.4
Version 5.4.5
Version 5.4.6
Version 5.4.7
Version 5.4.9
Version 5.4
Version 5.5
Version 5.6
Version 5.7.1
Version 5.7.2
Version 5.7.3
Version 5.7.4
Version 5.7.5
Version 5.7
Version 5.8.1
Version 6.0
Version 6.1.1
Version 6.1.2
Version 6.1.3
Version 6.1.4
Version 6.1
Version 6.2.10
Version 6.2.1
Version 6.2.2
Version 6.2.3
Version 6.2.4
Version 6.2.5
Version 6.2.6
Version 6.2.7
Version 6.2.9
Version 6.2

Timeline

No history available yet.