CVE-2018-25199

OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through multiple parameters. Attackers can inject SQL commands via the search parameter in search.php, pageid parameter in page.php, and id parameter in posts.php to extract database information including table names, schema names, and database credentials.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:tomalofficial:php_oop_cms_blog:1.0:*:*:*:*:*:*:*

History

11 Mar 2026, 00:37

Type Values Removed Values Added
First Time Tomalofficial
Tomalofficial php Oop Cms Blog
CPE cpe:2.3:a:tomalofficial:php_oop_cms_blog:1.0:*:*:*:*:*:*:*
References () https://www.exploit-db.com/exploits/45799 - () https://www.exploit-db.com/exploits/45799 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/oop-cms-blog-sql-injection-via-search-parameter - () https://www.vulncheck.com/advisories/oop-cms-blog-sql-injection-via-search-parameter - Third Party Advisory
Summary
  • (es) OOP CMS BLOG 1.0 contiene vulnerabilidades de inyección SQL que permiten a atacantes no autenticados ejecutar consultas SQL arbitrarias inyectando código malicioso a través de múltiples parámetros. Los atacantes pueden inyectar comandos SQL a través del parámetro search en search.php, el parámetro pageid en page.php, y el parámetro id en posts.php para extraer información de la base de datos incluyendo nombres de tablas, nombres de esquemas, y credenciales de la base de datos.

06 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-06 13:16

Updated : 2026-03-11 00:37


NVD link : CVE-2018-25199

Mitre link : CVE-2018-25199

CVE.ORG link : CVE-2018-25199


JSON object : View

Products Affected

tomalofficial

  • php_oop_cms_blog
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')