yuanhui

3 exploits Active since Oct 2025
CVE-2025-12306 WRITEUP HIGH WRITEUP
Nero Social Networking Site 1.0 - SQL Injection via ID Parameter in acceptoffres.php
A vulnerability was determined in code-projects Nero Social Networking Site 1.0. Affected is an unknown function of the file /acceptoffres.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
CVSS 7.3
CVE-2025-12307 WRITEUP HIGH WRITEUP
Nero Social Networking Site 1.0 - SQL Injection via ID Parameter in addfriend.php
A vulnerability was identified in code-projects Nero Social Networking Site 1.0. Affected by this vulnerability is an unknown functionality of the file /addfriend.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
CVSS 7.3
CVE-2025-12308 WRITEUP HIGH WRITEUP
Nero Social Networking Site 1.0 - SQL Injection via deletemessage.php message_id Parameter
A security flaw has been discovered in code-projects Nero Social Networking Site 1.0. Affected by this issue is some unknown functionality of the file /deletemessage.php. Performing manipulation of the argument message_id results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.
CVSS 7.3