{"api_version":"1","generated_at":"2026-07-23T07:48:16+00:00","cve":"CVE-2008-2566","urls":{"html":"https://cve.report/CVE-2008-2566","api":"https://cve.report/api/cve/CVE-2008-2566.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-2566","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-2566"},"summary":{"title":"CVE-2008-2566","description":"Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-06-06 18:32:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/30540","name":"http://secunia.com/advisories/30540","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"PHP Address Book Cross-Site Scripting and SQL Injection - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/129789/PHP-Address-Book-Cross-Site-Scripting-SQL-Injection.html","name":"http://packetstormsecurity.com/files/129789/PHP-Address-Book-Cross-Site-Scripting-SQL-Injection.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"PHP Address Book Cross Site Scripting / SQL Injection ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42856","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42856","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/5739","name":"https://www.exploit-db.com/exploits/5739","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP-Address Book <= 3.1.5 (SQL/XSS) Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99624","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99624","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-2566","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-2566","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"2566","vulnerable":"1","versionEndIncluding":"3.1.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"php-address_book","cpe5":"php-address_book","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:05:30.230Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"30540","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30540"},{"name":"phpaddressbook-group-xss(42856)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42856"},{"name":"5739","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/5739"},{"name":"phpaddressbook-grouppara-xss(99624)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99624"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/129789/PHP-Address-Book-Cross-Site-Scripting-SQL-Injection.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-06-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"30540","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30540"},{"name":"phpaddressbook-group-xss(42856)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42856"},{"name":"5739","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/5739"},{"name":"phpaddressbook-grouppara-xss(99624)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99624"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/129789/PHP-Address-Book-Cross-Site-Scripting-SQL-Injection.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-2566","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"30540","refsource":"SECUNIA","url":"http://secunia.com/advisories/30540"},{"name":"phpaddressbook-group-xss(42856)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42856"},{"name":"5739","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/5739"},{"name":"phpaddressbook-grouppara-xss(99624)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99624"},{"name":"http://packetstormsecurity.com/files/129789/PHP-Address-Book-Cross-Site-Scripting-SQL-Injection.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/129789/PHP-Address-Book-Cross-Site-Scripting-SQL-Injection.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-2566","datePublished":"2008-06-06T18:00:00.000Z","dateReserved":"2008-06-06T00:00:00.000Z","dateUpdated":"2024-08-07T09:05:30.230Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-06-06 18:32:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php-address_book:php-address_book:*:*:*:*:*:*:*:*","versionEndIncluding":"3.1.5","matchCriteriaId":"CC537BA2-A3BA-46A8-98C9-363817064F0C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"2566","Ordinal":"1","Title":"CVE-2008-2566","CVE":"CVE-2008-2566","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"2566","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI.","Type":"Description","Title":"CVE-2008-2566"},{"CveYear":"2008","CveId":"2566","Ordinal":"2","NoteData":"2008-06-06","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"2566","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}