CVE-2019-25459
CRITICALWeb-ofisi Emlak V2 - Unauthenticated SQL Injection via GET Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25459. PoCs published by Ahmet Ümit BAYRAM.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Web Ofisi Emlak 3 via multiple GET parameters. It includes functional payloads that manipulate SQL queries to confirm vulnerability (e.g., boolean-based and time-based injections).
Description
Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in the endpoint that allow unauthenticated attackers to manipulate database queries through GET parameters. Attackers can inject SQL code into parameters like emlak_durumu, emlak_tipi, il, ilce, kelime, and semt to extract sensitive database information or perform time-based blind SQL injection attacks.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in Web Ofisi Emlak 3 via multiple GET parameters. It includes functional payloads that manipulate SQL queries to confirm vulnerability (e.g., boolean-based and time-based injections).
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H