PT-2026-24974 · Jettweb · Hazir Haber Sitesi Scripti+1

CVE-2019-25514

·

Publicado

2026-03-12

·

Atualizado

2026-03-12

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jettweb PHP Hazir Haber Sitesi Scripti version 3
Description The software contains an SQL injection issue that allows attackers to inject malicious SQL commands. This is possible through manipulation of the kelime parameter in POST requests. Attackers can use UNION-based SQL injection payloads to extract sensitive data from the database or bypass authentication controls.
Recommendations Versions prior to version 3 are recommended.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-25514

Produtos afetados

Hazir Haber Sitesi Scripti
Php Stock News Site Script