{"api_version":"1","generated_at":"2026-07-23T09:58:58+00:00","cve":"CVE-2006-4575","urls":{"html":"https://cve.report/CVE-2006-4575","api":"https://cve.report/api/cve/CVE-2006-4575.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-4575","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-4575"},"summary":{"title":"CVE-2006-4575","description":"Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id, (6) language, (7) defaultLetter, (8) newuserPass, (9) newuserType, (10) newuserEmail parameters in (a) user.php; the (11) goTo and (12) search parameters in (b) search.php; and the (13) groupAddName parameter in (c) save.php.","state":"PUBLISHED","assigner":"flexera","published_at":"2006-12-31 05:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31238","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31238","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21694","name":"http://secunia.com/advisories/21694","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"The Address Book Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/32570","name":"http://osvdb.org/32570","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/32569","name":"http://osvdb.org/32569","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/32568","name":"http://osvdb.org/32568","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/21870","name":"http://www.securityfocus.com/bid/21870","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"The Address Book Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/secunia_research/2006-76/advisory/","name":"http://secunia.com/secunia_research/2006-76/advisory/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"The Address Book Multiple Vulnerabilities - Secunia Research - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-4575","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4575","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"4575","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"the_address_book","cpe5":"the_address_book","cpe6":"1.04e","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T19:14:47.688Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2006-76/advisory/"},{"name":"theaddressbook-multiple-sql-injection(31238)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31238"},{"name":"32568","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/32568"},{"name":"21870","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21870"},{"name":"32569","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/32569"},{"name":"21694","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/21694"},{"name":"32570","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/32570"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-01-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id, (6) language, (7) defaultLetter, (8) newuserPass, (9) newuserType, (10) newuserEmail parameters in (a) user.php; the (11) goTo and (12) search parameters in (b) search.php; and the (13) groupAddName parameter in (c) save.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","shortName":"flexera"},"references":[{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2006-76/advisory/"},{"name":"theaddressbook-multiple-sql-injection(31238)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31238"},{"name":"32568","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/32568"},{"name":"21870","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21870"},{"name":"32569","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/32569"},{"name":"21694","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/21694"},{"name":"32570","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/32570"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"PSIRT-CNA@flexerasoftware.com","ID":"CVE-2006-4575","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id, (6) language, (7) defaultLetter, (8) newuserPass, (9) newuserType, (10) newuserEmail parameters in (a) user.php; the (11) goTo and (12) search parameters in (b) search.php; and the (13) groupAddName parameter in (c) save.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://secunia.com/secunia_research/2006-76/advisory/","refsource":"MISC","url":"http://secunia.com/secunia_research/2006-76/advisory/"},{"name":"theaddressbook-multiple-sql-injection(31238)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31238"},{"name":"32568","refsource":"OSVDB","url":"http://osvdb.org/32568"},{"name":"21870","refsource":"BID","url":"http://www.securityfocus.com/bid/21870"},{"name":"32569","refsource":"OSVDB","url":"http://osvdb.org/32569"},{"name":"21694","refsource":"SECUNIA","url":"http://secunia.com/advisories/21694"},{"name":"32570","refsource":"OSVDB","url":"http://osvdb.org/32570"}]}}}},"cveMetadata":{"assignerOrgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","assignerShortName":"flexera","cveId":"CVE-2006-4575","datePublished":"2007-01-03T20:00:00.000Z","dateReserved":"2006-09-06T00:00:00.000Z","dateUpdated":"2024-08-07T19:14:47.688Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-12-31 05:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:the_address_book:the_address_book:1.04e:*:*:*:*:*:*:*","matchCriteriaId":"987F84E0-1A6B-484B-B973-9AE2E3ADB435"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"4575","Ordinal":"1","Title":"CVE-2006-4575","CVE":"CVE-2006-4575","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"4575","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id, (6) language, (7) defaultLetter, (8) newuserPass, (9) newuserType, (10) newuserEmail parameters in (a) user.php; the (11) goTo and (12) search parameters in (b) search.php; and the (13) groupAddName parameter in (c) save.php.","Type":"Description","Title":"CVE-2006-4575"},{"CveYear":"2006","CveId":"4575","Ordinal":"2","NoteData":"2007-01-03","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"4575","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}