VYPR

Easy Address Book Web Server

by Easy Address Book Web Server Project

CVEs (3)

  • CVE-2023-4491CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could allow an attacker to send a very long username string to /searchbook.ghp, asking for the name via a POST request, resulting in arbitrary code execution on the…

  • CVE-2023-4493MedOct 4, 2023
    risk 0.40cvss 6.1epss 0.00

    Stored Cross-Site Scripting in Easy Address Book Web Server 1.6 version, through the users_admin.ghp file that affects multiple parameters such as (firstname, homephone, lastname, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate, workzip). This…

  • CVE-2023-4492MedOct 4, 2023
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate and workzip) of the /addrbook.ghp file, allowing an attacker to inject a JavaScript payload…