{"api_version":"1","generated_at":"2026-07-23T08:59:41+00:00","cve":"CVE-2009-2608","urls":{"html":"https://cve.report/CVE-2009-2608","api":"https://cve.report/api/cve/CVE-2009-2608.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-2608","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-2608"},"summary":{"title":"CVE-2009-2608","description":"Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php.  NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-07-27 18:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-89","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/35511","name":"http://www.securityfocus.com/bid/35511","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"PHP Address Book Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.exploit-db.com/exploits/9023","name":"http://www.exploit-db.com/exploits/9023","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP-Address Book 4.0.x - Multiple SQL Injections - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/504595/100/0/threaded","name":"http://www.securityfocus.com/archive/1/504595/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/35590","name":"http://secunia.com/advisories/35590","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"PHP-addressbook SQL Injection Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-2608","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-2608","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"2608","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"chatelao","cpe5":"php_address_book","cpe6":"4.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2608","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"chatelao","cpe5":"php_address_book","cpe6":"4.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:59:56.968Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"35511","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/35511"},{"name":"35590","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35590"},{"name":"20090626 MULTIPLE SQL INJECTION VULNERABILITIES --PHP-AddressBook v-4.0.x-->","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/504595/100/0/threaded"},{"name":"9023","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/9023"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-06-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php.  NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"35511","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/35511"},{"name":"35590","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35590"},{"name":"20090626 MULTIPLE SQL INJECTION VULNERABILITIES --PHP-AddressBook v-4.0.x-->","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/504595/100/0/threaded"},{"name":"9023","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/9023"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-2608","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php.  NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"35511","refsource":"BID","url":"http://www.securityfocus.com/bid/35511"},{"name":"35590","refsource":"SECUNIA","url":"http://secunia.com/advisories/35590"},{"name":"20090626 MULTIPLE SQL INJECTION VULNERABILITIES --PHP-AddressBook v-4.0.x-->","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/504595/100/0/threaded"},{"name":"9023","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/9023"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-2608","datePublished":"2009-07-27T18:00:00.000Z","dateReserved":"2009-07-27T00:00:00.000Z","dateUpdated":"2024-08-07T05:59:56.968Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-07-27 18:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-89","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:chatelao:php_address_book:4.0.1:*:*:*:*:*:*:*","matchCriteriaId":"7CB55AC9-5FE9-4D82-96F6-55BA869DED41"},{"vulnerable":true,"criteria":"cpe:2.3:a:chatelao:php_address_book:4.0.2:*:*:*:*:*:*:*","matchCriteriaId":"42B80912-2590-41E4-9F02-94F830E5829C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"2608","Ordinal":"1","Title":"CVE-2009-2608","CVE":"CVE-2009-2608","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"2608","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php.  NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565.","Type":"Description","Title":"CVE-2009-2608"},{"CveYear":"2009","CveId":"2608","Ordinal":"2","NoteData":"2009-07-27","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"2608","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}