CVE-2018-17843
Last modified
CVE-2018-17843 is a vulnerability of currently unknown severity. SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyorder MLM Software 1.0, Repurchase MLM Software 1.0, and Gift MLM Software 1.0 via the member/readmsg.php msg_id parameter, the member/tree.php pid parameter, or the member/downline.php m_id parameter.. EPSS estimates a 2.01% chance of exploitation in the next 30 days.
Description
SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyorder MLM Software 1.0, Repurchase MLM Software 1.0, and Gift MLM Software 1.0 via the member/readmsg.php msg_id parameter, the member/tree.php pid parameter, or the member/downline.php m_id parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mlmsoftwarez | Add Clicking Mlm Software | 1.0 |
| Mlmsoftwarez | Autopool Mlm Software | 1.0 |
| Mlmsoftwarez | Bidding Mlm Software | 1.0 |
| Mlmsoftwarez | Binary Mlm Software | 1.0 |
| Mlmsoftwarez | Gift Mlm Software | 1.0 |
| Mlmsoftwarez | Investmen Mlm Software | 1.0 |
| Mlmsoftwarez | Level Mlm Software | 1.0 |
| Mlmsoftwarez | Moneyorder Mlm Software | 1.0 |
| Mlmsoftwarez | Repurchase Mlm Software | 1.0 |
| Mlmsoftwarez | Singleleg Mlm Software | 1.0 |
References
- https://www.exploit-db.com/author/?a=8844Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/45511Third Party Advisory, VDB Entry
- https://www.exploit-db.com/author/?a=8844Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/45511Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-17843?
How severe is CVE-2018-17843?
How do I fix CVE-2018-17843?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-17837An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file…
- CVE-2018-17838An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file…
- CVE-2018-1784IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL I…7.1
- CVE-2018-17840SQL injection exists in Scriptzee Education Website 1.0 via …
- CVE-2018-17841SQL injection exists in Scriptzee Flippa Marketplace Clone 1…
- CVE-2018-17842SQL injection exists in Scriptzee Hotel Booking Engine 1.0 v…9.8
- CVE-2018-17846The html package (aka x/net/html) through 2018-09-25 in Go m…7.5
- CVE-2018-17847The html package (aka x/net/html) through 2018-09-25 in Go m…7.5
- CVE-2018-17848The html package (aka x/net/html) through 2018-09-25 in Go m…7.5
- CVE-2018-17849Navigate CMS 2.8 has Stored XSS via a navigate_upload.php (a…
- CVE-2018-1785IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1…7.5
- CVE-2018-17850Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
Are you affected by CVE-2018-17843?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
