vendor:
addressbook
by:
David Velazquez a.k.a. d4sh&r000
5.5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: addressbook
Affected Version From: 9.0.0.1
Affected Version To: 9.0.0.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Ubuntu Server 20.04 LTS
2020
addressbook 9.0.0.1 – ‘id’ SQL Injection
addressbook 9.0.0.1 is vulnerable to time-based blind SQL injection. The vulnerability allows an attacker to manipulate the 'id' parameter in the URL to execute arbitrary SQL queries.
Mitigation:
The vendor should sanitize user input and use parameterized queries to prevent SQL injection attacks. Users should ensure they are using the latest version of the software.