Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the poll parameter. Attackers can send POST requests to arama.php with malicious SQL payloads in the poll parameter to extract sensitive data or modify database contents.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Mar 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the poll parameter. Attackers can send POST requests to arama.php with malicious SQL payloads in the poll parameter to extract sensitive data or modify database contents. | |
| Title | Jettweb PHP Hazir Haber Sitesi Scripti V1 SQL Injection via arama.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-12T18:48:39.515Z
Reserved: 2026-03-12T13:52:30.001Z
Link: CVE-2019-25518
No data.
Status : Received
Published: 2026-03-12T16:16:04.610
Modified: 2026-03-12T16:16:04.610
Link: CVE-2019-25518
No data.
OpenCVE Enrichment
No data.