CVE-2019-25456

Szczegóły podatności CVE.
Aktualizacja: 04.03.2026, 01:54 (CET)
non-KEV CVSS 9.1 EPSS 0.0012 Score 27.37

Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'ara' GET parameter. Attackers can send requests to with time-based SQL injection payloads to extract sensitive database information or cause denial of service.

Źródła

ŹródłoLinkUwagi
NVD (NIST)https://nvd.nist.gov/vuln/detail/CVE-2019-25456Karta CVE w NVD
CISA KEVhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-25456Wyszukiwanie CVE w KEV
FIRST EPSShttps://api.first.org/data/v1/epss?cve=CVE-2019-25456API EPSS dla CVE
disclosure@vulncheck.comhttps://www.exploit-db.com/exploits/47141Exploit, VDB Entry
disclosure@vulncheck.comhttps://www.vulncheck.com/advisories/web-ofisi-emlak-sql-injection-via-ara-parameterBroken Link
disclosure@vulncheck.comhttps://www.web-ofisi.com/detay/emlak-scripti-v2.htmlProduct