CVE-2015-1518

Redaxscript <2.3.0 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.

Exploits (1)

exploitdb WORKING POC
by ITAS Team · textwebappsphp
https://www.exploit-db.com/exploits/36023

References (5)

Core 5

Scores

EPSS 0.0249
EPSS Percentile 85.4%

Details

CWE
CWE-89
Status published
Products (1)
redaxscript/redaxscript < 2.2.0
Published Feb 11, 2015
Tracked Since Feb 18, 2026