CVE-2012-1911: Chatelao PHP Address Book

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) to_group parameter to group.php or (2) id parameter to vcard.php. NOTE: the edit.php vector is already covered by CVE-2008-2565.

Affected products

  • Chatelao PHP Address Book: up to and including 6.2.11; version 1.0 only; version 1.2 only; version 2.0 only; version 2.1 only; version 2.1.1 only; …

Published 2012-09-09. Last modified 2026-06-16.