CVE-2018-5972

CRITICAL

Classified Ads CMS Quickad 4.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-5972. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Classified Ads CMS - Quickad 4.0, targeting multiple GET parameters (keywords, placeid, subcat, cat) with boolean-based blind, error-based, and UNION query techniques.

Description

SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/43868

This exploit demonstrates SQL injection vulnerabilities in Classified Ads CMS - Quickad 4.0, targeting multiple GET parameters (keywords, placeid, subcat, cat) with boolean-based blind, error-based, and UNION query techniques.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Classified Ads CMS - Quickad 4.0
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43868/

Scores

CVSS v3 9.8
EPSS 0.1949
EPSS Percentile 97.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
quickad_project/quickad 4.0
Published Jan 24, 2018
Tracked Since Feb 18, 2026