CVE-2019-25442
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows attackers to access sensitive information from the database by sending specially crafted requests to a specific page without needing to log in. They can exploit this weakness by manipulating a parameter in the URL, which lets them run harmful SQL commands.
Technical Description
Web Wiz Forums 12.01 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the PF parameter. Attackers can send GET requests to member_profile.asp with malicious PF values to extract sensitive database information.
CVSS Vector Analysis
Vector String
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 22, 2026
about 1 month ago
Last Modified
Feb 26, 2026
about 1 month ago
Vendor
webwiz
Product
web wiz forums