Back to Database
Status published
High
CVE-2006-4580
register.php in The Address Book 1.04e allows remote attackers to...
Vulnerability Description
register.php in The Address Book 1.04e allows remote attackers to bypass the "Allow User Self-Registration" setting and create arbitrary users by setting the mode parameter to "confirm".
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-4580
Credits & Attribution
No credits recorded in the NVD database.
References
More from the address book
View All →CVE-2006-4582
Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e...
Medium
5
CVE-2006-4581
Unrestricted file upload vulnerability in The Address Book 1.04e validates...
Medium
5
CVE-2006-4579
Directory traversal vulnerability in users.php in The Address Book 1.04e...
Medium
5
CVE-2006-4578
export.php in The Address Book 1.04e writes username and password...
High
7.5
CVE-2006-4577
Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e...
Medium
6.8
Affected Vendor
the address book
View all reports →Affected Software
the address book
Vulnerable Versions:
1.04e
Timeline
Official Publish:
January 3rd, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.