CVE-2018-25199 - OOP CMS BLOG 1.0 SQL Injection via search parameter

CVE-2018-25199 - OOP CMS BLOG 1.0 SQL Injection via search parameter

CVE ID : CVE-2018-25199 Published : March 6, 2026, 12:19 p.m. | 39 minutes ago Description : OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through multiple parameters. Attackers can inject SQL commands via the search parameter in search.php, pageid parameter in page.php, and id parameter in posts.php to extract database information including table names, schema names, and database credentials. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
March 6, 2026
Affected Product: php
Impact: SQL injection