


Perceptive Security
SOC/SIEM Consultancy

MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands by injecting malicious…
Published:
29 mei 2026 om 22:00:00
Alert date:
30 mei 2026 om 17:07:56
Source:
nvd.nist.gov
Web Technologies, Database & Storage
CVE-2018-25422 is an SQL injection vulnerability in the MOGG web simulator Script that allows unauthenticated attackers to execute arbitrary SQL commands through the id parameter in play.php. Attackers can send crafted GET requests with malicious SQL payloads to extract sensitive database information including usernames and other data. The vulnerability affects all versions of the MOGG web simulator and can be exploited without authentication, making it a high-risk security issue for affected systems.
Technical details
Mitigation steps:
Affected products:
MOGG web simulator Script
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25422
https://github.com/spider312/mtgas
https://www.exploit-db.com/exploits/45717
https://www.vulncheck.com/advisories/mogg-web-simulator-script-all-version-sql-injection-via-play-php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
