Executive brief
Phpscriptsmall News Website Script, a software package used to build and manage news portals, contains a security flaw that allows unauthorized individuals to access its database. By sending a specially crafted web request, an attacker can bypass security controls to view sensitive information stored in the system. This could lead to the exposure of private user data, administrative credentials, or internal site content.
Technical details
A SQL injection vulnerability exists in Phpscriptsmall News Website Script 2.0.5 due to improper neutralization of special elements in the news ID parameter. An unauthenticated remote attacker can exploit this by sending a malicious GET request to the 'index.php/show/news/' endpoint. Successful exploitation allows the attacker to manipulate backend SQL queries, potentially leading to the extraction of sensitive information from the database. The vulnerability was originally discovered in 2019 and affects the news display functionality of the application.
Affected products
- Phpscriptsmall News Website Script 2.0.5
Timeline
- 2019-02-22: disclosed: Vulnerability discovered by researcher Mr Winst0n
- 2019-02-25: other: Exploit code published on Exploit-DB
- 2026-04-05: advisory: CVE-2019-25668 published in NVD