8.8

CVSS4.0

CVE-2019-25526 - Inout EasyRooms Ultimate Edition v1.0 SQL Injection via search

Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the location parameter. Attackers can send POST requests to the search/searchdetailed endpoint with malicious SQL payloadsโ€ฆ

๐Ÿ“… Published: March 12, 2026, 3:36 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:07 p.m.

8.8

CVSS4.0

CVE-2019-25525 - Inout EasyRooms Ultimate Edition v1.0 SQL Injection via search

Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the guests parameter. Attackers can send POST requests to the search/rentals endpoint with malicious SQL payloads to bypasโ€ฆ

๐Ÿ“… Published: March 12, 2026, 3:36 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:07 p.m.

8.8

CVSS4.0

CVE-2019-25524 - XooGallery Lastest Latest SQL Injection via results.php

XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'p' parameter. Attackers can send GET requests to results.php with malicious 'p' values to bypass authentication, extract sensitive data, โ€ฆ

๐Ÿ“… Published: March 12, 2026, 3:36 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:07 p.m.

8.8

CVSS4.0

CVE-2019-25523 - XooGallery Lastest Latest SQL Injection via cat.php

XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. Attackers can send GET requests to cat.php with malicious cat_id values to bypass authentication, extract sensitive dataโ€ฆ

๐Ÿ“… Published: March 12, 2026, 3:36 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:07 p.m.

8.8

CVSS4.0

CVE-2019-25522 - XooGallery Lastest Latest Multiple SQL Injections via photo.php

XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through the photo_id parameter. Attackers can send GET requests to photo.php with malicious photo_id values to extract sensitive data, bypass aโ€ฆ

๐Ÿ“… Published: March 12, 2026, 3:36 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:07 p.m.

8.8

CVSS4.0

CVE-2019-25521 - XooGallery Lastest Latest SQL Injection via gal.php gal_id

XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the gal_id parameter. Attackers can send GET requests to gal.php with malicious gal_id values to extract sensitive database information or modโ€ฆ

๐Ÿ“… Published: March 12, 2026, 3:36 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:07 p.m.

8.8

CVSS4.0

CVE-2019-25520 - Jettweb PHP Hazir Haber Sitesi Scripti V1 Authentication Bypass

Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated attackers to gain administrative access by exploiting improper SQL query validation. Attackers can submit SQL injection payloads in the username and passโ€ฆ

๐Ÿ“… Published: March 12, 2026, 3:36 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:07 p.m.

8.8

CVSS4.0

CVE-2019-25519 - Jettweb PHP Hazir Haber Sitesi Scripti V1 SQL Injection

Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code through the option parameter. Attackers can send POST requests to uyelik.php with crafted payloads in the option parameter to executโ€ฆ

๐Ÿ“… Published: March 12, 2026, 3:36 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:07 p.m.

8.8

CVSS4.0

CVE-2019-25518 - Jettweb PHP Hazir Haber Sitesi Scripti V1 SQL Injection via arama.php

Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the poll parameter. Attackers can send POST requests to arama.php with malicious SQL payloads in the poll parameter toโ€ฆ

๐Ÿ“… Published: March 12, 2026, 3:36 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:07 p.m.

8.8

CVSS4.0

CVE-2019-25517 - Jettweb PHP Hazir Haber Sitesi Scripti V1 SQL Injection via haberarsiv.php

Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send requests to haberarsiv.php with malicious cid values using UNION-based injectionโ€ฆ

๐Ÿ“… Published: March 12, 2026, 3:36 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:07 p.m.
Total resulsts: 337984
Page 39 of 33,799
ยซ previous page ยป next page
Filters