Phpabook
Phpabook · 3 CVEs
CVE-2022-30352
CRITICAL
phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user"…
May 27, 2022
CVE-2020-8510
CRITICAL
An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value o…
Feb 3, 2020
CVE-2008-4490
MEDIUM
Directory traversal vulnerability in config.inc.php in phpAbook 0.8.8b and earlier, when magic_quotes_gpc is disabled,…
Oct 8, 2008
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2022-30352 | phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script. | CRITICAL | 1.86% | May 27, 2022 |
| CVE-2020-8510 | An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can… | CRITICAL | 1.25% | Feb 3, 2020 |
| CVE-2008-4490 | Directory traversal vulnerability in config.inc.php in phpAbook 0.8.8b and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and e… | MEDIUM | 1.91% | Oct 8, 2008 |
Showing 1 to 3 of 3 CVEs