Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit malicious SQL code through the login POST parameter to extract database information including usernames, passwords, and system credentials.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Net-billetterie
Net-billetterie billetterie |
|
| Vendors & Products |
Net-billetterie
Net-billetterie billetterie |
Fri, 06 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit malicious SQL code through the login POST parameter to extract database information including usernames, passwords, and system credentials. | |
| Title | Net-Billetterie 2.9 SQL Injection via login.inc.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-06T12:18:58.920Z
Reserved: 2026-03-06T11:26:26.737Z
Link: CVE-2018-25167
No data.
Status : Awaiting Analysis
Published: 2026-03-06T13:15:57.653
Modified: 2026-03-09T13:35:34.633
Link: CVE-2018-25167
No data.