CVE-2018-17843

CRITICAL

ADD Clicking MLM Software <1.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-17843. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in Singleleg MLM Software 1.0 via the 'msg_id' parameter in 'readmsg.php'. The URL-encoded payload uses UNION-based SQLi to extract database information, confirming the vulnerability.

Description

SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyorder MLM Software 1.0, Repurchase MLM Software 1.0, and Gift MLM Software 1.0 via the member/readmsg.php msg_id parameter, the member/tree.php pid parameter, or the member/downline.php m_id parameter.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/45511

The exploit demonstrates a SQL injection vulnerability in Singleleg MLM Software 1.0 via the 'msg_id' parameter in 'readmsg.php'. The URL-encoded payload uses UNION-based SQLi to extract database information, confirming the vulnerability.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Singleleg MLM Software 1.0
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/author/?a=8844
Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/45511

Scores

CVSS v3 9.8
EPSS 0.0201
EPSS Percentile 78.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (10)
mlmsoftwarez/add_clicking_mlm_software 1.0
mlmsoftwarez/autopool_mlm_software 1.0
mlmsoftwarez/bidding_mlm_software 1.0
mlmsoftwarez/binary_mlm_software 1.0
mlmsoftwarez/gift_mlm_software 1.0
mlmsoftwarez/investmen_mlm_software 1.0
mlmsoftwarez/level_mlm_software 1.0
mlmsoftwarez/moneyorder_mlm_software 1.0
mlmsoftwarez/repurchase_mlm_software 1.0
mlmsoftwarez/singleleg_mlm_software 1.0
Published May 24, 2019
Tracked Since Feb 18, 2026