Web Ofisi Firma Rehberi v1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters. Attackers can send requests to with malicious payloads in the 'il', 'kat', or 'kelime' parameters to extract sensitive database information or perform time-based blind SQL injection attacks.
Metrics
Affected Vendors & Products
References
History
Sun, 22 Feb 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Web Ofisi Firma Rehberi v1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters. Attackers can send requests to with malicious payloads in the 'il', 'kat', or 'kelime' parameters to extract sensitive database information or perform time-based blind SQL injection attacks. | |
| Title | Web Ofisi Firma Rehberi v1 SQL Injection via firmalar.html | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-22T14:12:12.162Z
Reserved: 2026-02-22T13:58:01.340Z
Link: CVE-2019-25458
No data.
Status : Received
Published: 2026-02-22T15:16:15.570
Modified: 2026-02-22T15:16:15.570
Link: CVE-2019-25458
No data.
OpenCVE Enrichment
No data.