Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the category parameter. Attackers can send GET requests to the category endpoint with URL-encoded SQL UNION statements to extract database information including usernames, database names, and MySQL version details.
Metrics
Affected Vendors & Products
References
History
Sat, 21 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the category parameter. Attackers can send GET requests to the category endpoint with URL-encoded SQL UNION statements to extract database information including usernames, database names, and MySQL version details. | |
| Title | Kepler Wallpaper Script 1.1 SQL Injection via category | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-21T15:30:34.815Z
Reserved: 2026-03-21T15:24:10.532Z
Link: CVE-2019-25576
No data.
Status : Received
Published: 2026-03-21T16:16:01.333
Modified: 2026-03-21T16:16:01.333
Link: CVE-2019-25576
No data.
OpenCVE Enrichment
No data.