CVE-2018-5978

CRITICAL

Facebook Style Php Ajax Chat Zechat 1.5 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-5978. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in Facebook Style Php Ajax Chat - Zechat 1.5. It provides a proof-of-concept payload for the login.php endpoint, allowing an attacker to inject SQL commands via the username field.

Description

SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/43865

The exploit demonstrates a SQL injection vulnerability in Facebook Style Php Ajax Chat - Zechat 1.5. It provides a proof-of-concept payload for the login.php endpoint, allowing an attacker to inject SQL commands via the username field.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Facebook Style Php Ajax Chat - Zechat 1.5
No auth needed
Prerequisites: Access to the login.php endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43865/

Scores

CVSS v3 9.8
EPSS 0.0270
EPSS Percentile 84.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
zechat_project/zechat 1.5
Published Jan 24, 2018
Tracked Since Feb 18, 2026