### [CVE-2018-18075](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18075) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort parameter. ### POC #### Reference - https://seccops.com/wikidforum-2-20-multiple-sql-injection-vulnerabilities/ - https://seccops.com/wikidforum-2-20-multiple-sql-injection-vulnerabilities/ - https://www.exploit-db.com/exploits/45564/ - https://www.exploit-db.com/exploits/45564/ #### Github No PoCs found on GitHub currently.