High severity8.2NVD Advisory· Published Mar 12, 2026· Updated Jun 17, 2026
CVE-2019-25516
CVE-2019-25516
Description
Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the gallery_id parameter. Attackers can send GET requests to gallery.php with malicious gallery_id values using UNION-based SQL injection to extract sensitive database information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
31.0+ 1 more
- (no CPE)range: 1.0
- (no CPE)range: V1
- cpe:2.3:a:jettweb:php_stock_news_site_script:1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/46597nvdExploitVDB Entry
- www.vulncheck.com/advisories/jettweb-php-hazir-haber-sitesi-scripti-v1-sql-injection-via-gallery-phpnvdThird Party Advisory
News mentions
0No linked articles in our index yet.