VDB
GCVE-110-PHPLD-2026-001
GCVE-110-PHPLD-2026-001
Advisory Published
PHP Link Directory 2.1.3 contains several security issues:
[1] SQL Injection in admin/dir_validate.php (POST CATEGORY_ID)
[2] SQL Injection in admin panel via ORDER BY (GET sort -> session)
[3] Insecure Direct Object Reference in add_reciprocal.php (no auth)
[4] CSRF on admin state-changing GET actions (dir_links_edit.php)
[5] Exposed install/ directory after deployment (configuration risk)
Public-facing search (index.php?q=) and submit.php CAPTCHA are NOT SQL
injectable in default code (parameters are escaped). Do not report those
as SQLi without a separate bypass.
Browse GCVE Records
385 records in the GCVE database · Updated September 12, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.