Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can submit crafted SQL payloads in the 's' parameter of search requests to extract sensitive database information including version details and other data.
References
| Link | Resource |
|---|---|
| http://www.phpscriptsmall.com/ | Product |
| https://www.exploit-db.com/exploits/46457 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/advance-gift-shop-pro-script-sql-injection-via-search | Third Party Advisory |
Configurations
History
24 Apr 2026, 15:45
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.phpscriptsmall.com/ - Product | |
| References | () https://www.exploit-db.com/exploits/46457 - Exploit, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/advance-gift-shop-pro-script-sql-injection-via-search - Third Party Advisory | |
| First Time |
Phpscriptsmall advance Gift Shop Pro Script
Phpscriptsmall |
|
| CPE | cpe:2.3:a:phpscriptsmall:advance_gift_shop_pro_script:*:*:*:*:*:*:*:* |
05 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-05 21:16
Updated : 2026-04-24 15:45
NVD link : CVE-2019-25680
Mitre link : CVE-2019-25680
CVE.ORG link : CVE-2019-25680
JSON object : View
Products Affected
phpscriptsmall
- advance_gift_shop_pro_script
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
