Back to Database
Status published
Medium
CVE-2006-4581
Unrestricted file upload vulnerability in The Address Book 1.04e validates...
Vulnerability Description
Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-4581
Credits & Attribution
No credits recorded in the NVD database.
References
More from the address book
View All →CVE-2006-4582
Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e...
Medium
5
CVE-2006-4580
register.php in The Address Book 1.04e allows remote attackers to...
High
7.5
CVE-2006-4579
Directory traversal vulnerability in users.php in The Address Book 1.04e...
Medium
5
CVE-2006-4578
export.php in The Address Book 1.04e writes username and password...
High
7.5
CVE-2006-4577
Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e...
Medium
6.8
Affected Vendor
the address book
View all reports →Affected Software
the address book
Vulnerable Versions:
1.04e
Timeline
Official Publish:
January 3rd, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.