CVE-2019-25503 - CVE House
Back to Database
Status published High CVE-2019-25503

PHPads 2.0 SQL Injection via click.php3 bannerID

Vulnerability Description

PHPads 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the bannerID parameter in click.php3. Attackers can submit crafted bannerID values using SQL comment syntax and functions like extractvalue to extract sensitive database information such as the current database name.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25503

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Felipe Andrian Peixoto

Affected Vendor

Affected Software

PHPads
Vulnerable Versions:
2.0

Timeline

Official Publish: March 4th, 2026
Last Modified: July 15th, 2026
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

Weaknesses (CWE)