The Address Book is a focused contact-management application with a narrow vulnerability footprint centered on its single product line. The recurring disclosures reflect general software defect patterns that warrant attention to maintenance cadence and vendor responsiveness, though the specific weakness classes merit review against current exposure in your environment. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by The Address Book over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4575HIGH Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) | Dec 31, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-4578HIGH export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote att | Dec 31, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-4580HIGH register.php in The Address Book 1.04e allows remote attackers to bypass the "Allow User Self-Registration" setting and create arbitrary users by setting the mode parameter to "con | Dec 31, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-4056HIGH Multiple SQL injection vulnerabilities in the authentication process in katzlbt (a) The Address Book 1.04e and earlier and (b) The Address Book Reloaded before 2.0-rc4 allow remote | Aug 10, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-4576MEDIUM Cross-site scripting (XSS) vulnerability in The Address Book 1.04e allows remote attackers to inject arbitrary web script or HTML by uploading the HTML file with a GIF or JPG exten | Dec 31, 2006 | 6.8 | 18 | NO | NO |
CVE-2006-4577MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) email, | Dec 31, 2006 | 6.8 | 18 | NO | NO |
CVE-2006-4579MEDIUM Directory traversal vulnerability in users.php in The Address Book 1.04e allows remote attackers to include arbitrary files via a .. (dot dot) in the language parameter. | Dec 31, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-4581MEDIUM Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP | Dec 31, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-4582MEDIUM Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote attackers to perform unauthorized actions as other users via unspecified vectors, as demonst | Dec 31, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by The Address Book.
Media articles that mention a CVE ID that affects a product developed by The Address Book — matched by CVE ID, not by vendor name.