---
id: CVE-2018-25196
title: >-
  ServerZilla 1.0 contains an SQL injection vulnerability that allows
  unauthenticated attackers to manipulate database queries by injecting SQL code
  through the email parameter
summary: >-
  ServerZilla 1.0 contains an SQL injection vulnerability that allows
  unauthenticated attackers to manipulate database queries by injecting SQL code
  through the email parameter. Attackers can send POST requests to reset.php
  with malicious …
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-89
published: '2026-03-06'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T08:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-25196'
references:
  - url: 'https://www.exploit-db.com/exploits/45817'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/serverzilla-sql-injection-via-email-parameter
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00289
epssPercentile: 0.19567
ingestedAt: '2026-10-07T08:20:03.897Z'
---

## Overview

ServerZilla 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to reset.php with malicious email values containing SQL operators to bypass authentication and extract sensitive database information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
