755
VMScore

CVE-2018-5972

Published: 24/01/2018 Updated: 08/02/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI.

Vulnerable Product Search on Vulmon Subscribe to Product

quickad project quickad 4.0

Exploits

# # # # # # Exploit Title: Classified Ads CMS - Quickad 40 - SQL Injection # Dork: N/A # Date: 23012018 # Vendor Homepage: bylancercom/ # Software Link: codecanyonnet/item/quickad-classified-ads-php-script/19960675 # Version: 40 # Category: Webapps # Tested on: WiN7_x64/KaLiLinuX_x64 # CVE: CVE-2018-5972 # # # # # # Exploit Au ...
Quickad version 40 suffers from a remote SQL injection vulnerability ...