CVE-2019-25680

Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can submit crafted SQL payloads in the 's' parameter of search requests to extract sensitive database information including version details and other data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpscriptsmall:advance_gift_shop_pro_script:*:*:*:*:*:*:*:*

History

24 Apr 2026, 15:45

Type Values Removed Values Added
References () http://www.phpscriptsmall.com/ - () http://www.phpscriptsmall.com/ - Product
References () https://www.exploit-db.com/exploits/46457 - () https://www.exploit-db.com/exploits/46457 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/advance-gift-shop-pro-script-sql-injection-via-search - () https://www.vulncheck.com/advisories/advance-gift-shop-pro-script-sql-injection-via-search - Third Party Advisory
First Time Phpscriptsmall advance Gift Shop Pro Script
Phpscriptsmall
CPE cpe:2.3:a:phpscriptsmall:advance_gift_shop_pro_script:*:*:*:*:*:*:*:*

05 Apr 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-05 21:16

Updated : 2026-04-24 15:45


NVD link : CVE-2019-25680

Mitre link : CVE-2019-25680

CVE.ORG link : CVE-2019-25680


JSON object : View

Products Affected

phpscriptsmall

  • advance_gift_shop_pro_script
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')