Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags through the cateid parameter in categorysearch.php or SQL code through the view parameter in list-details.php to execute arbitrary code or extract database information.
References
| Link | Resource |
|---|---|
| http://www.phpscriptsmall.com/ | Product |
| https://www.exploit-db.com/exploits/46426 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/ask-expert-script-cross-site-scripting-sql-injection | Third Party Advisory |
Configurations
History
20 Apr 2026, 17:53
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.phpscriptsmall.com/ - Product | |
| References | () https://www.exploit-db.com/exploits/46426 - Exploit, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/ask-expert-script-cross-site-scripting-sql-injection - Third Party Advisory | |
| CPE | cpe:2.3:a:phpscriptsmall:ask_expert_script:3.0.5:*:*:*:*:*:*:* | |
| CWE | CWE-89 | |
| First Time |
Phpscriptsmall ask Expert Script
Phpscriptsmall |
05 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-05 21:16
Updated : 2026-04-20 17:53
NVD link : CVE-2019-25676
Mitre link : CVE-2019-25676
CVE.ORG link : CVE-2019-25676
JSON object : View
Products Affected
phpscriptsmall
- ask_expert_script
