CVE Browser
CVE-2022-30352 CRITICAL
phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script.
CVSS 9.8 EPSS 1.86% May 27, 2022
CVE-2020-8510 CRITICAL
An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can…
CVSS 9.8 EPSS 1.25% Feb 3, 2020
CVE-2008-4490 MEDIUM
Directory traversal vulnerability in config.inc.php in phpAbook 0.8.8b and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and e…
CVSS 5.1 EPSS 1.91% Oct 8, 2008
Showing 1 to 3 CVEs · page 1