Vulnerabilities > CVE-2006-4578 - Remote vulnerability in the Address Book the Address Book 1.04E

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
the-address-book

Summary

export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote attackers to obtain sensitive information.

Vulnerable Configurations

Part Description Count
Application
The_Address_Book
1