Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-5972. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Classified Ads CMS - Quickad 4.0, targeting multiple GET parameters (keywords, placeid, subcat, cat) with boolean-based blind, error-based, and UNION query techniques.
Description
SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI.
Exploits (1)
exploitdb
WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/43868
This exploit demonstrates SQL injection vulnerabilities in Classified Ads CMS - Quickad 4.0, targeting multiple GET parameters (keywords, placeid, subcat, cat) with boolean-based blind, error-based, and UNION query techniques.
Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
Classified Ads CMS - Quickad 4.0
No auth needed
Prerequisites:
Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/43868/
Scores
CVSS v3
9.8
EPSS
0.1949
EPSS Percentile
97.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
quickad_project/quickad
4.0
Published
Jan 24, 2018
Tracked Since
Feb 18, 2026