Zechat 1.5 SQL Injection via v parameter (time-based blind)
Vulnerability Description
Zechat 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated attackers to extract database information using time-based blind techniques. Attackers can exploit the v parameter with sleep-based blind injection to confirm vulnerability and extract data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25339
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Borna nematzadeh (L0RD) or borna.nematzadeh123@gmail.com
References
More from Bylancer
View All →Affected Vendor
Bylancer
View all reports →