CVE-2008-4178 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 3.4% (pctl 88)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and Downline Goldmine Builder allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 3.38% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-09-23 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| downline goldmine | builder |
| downline goldmine | new addon |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Downline Goldmine paidversion - SQL Injection | 2008-11-02 |
| exploit-db | Downline Goldmine newdownlinebuilder - SQL Injection | 2008-11-02 |
| exploit-db | Downline Goldmine Builder - SQL Injection | 2008-11-01 |
| exploit-db | Downline Goldmine Category Addon - SQL Injection | 2008-11-01 |
References
- http://packetstorm.linuxsecurity.com/0809-exploits/categoryaddon-sql.txt
- http://packetstorm.linuxsecurity.com/0809-exploits/downline-sql.txt
- http://packetstormsecurity.org/0809-exploits/newdownline-sql.txt
- http://secunia.com/advisories/31812
- http://www.securityfocus.com/bid/31169
- http://www.vupen.com/english/advisories/2008/2992
- http://www.vupen.com/english/advisories/2008/2993
- http://www.vupen.com/english/advisories/2008/2994
- http://www.vupen.com/english/advisories/2008/2995
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45128
- https://www.exploit-db.com/exploits/6946
- https://www.exploit-db.com/exploits/6947
- https://www.exploit-db.com/exploits/6950
- https://www.exploit-db.com/exploits/6951
- http://packetstorm.linuxsecurity.com/0809-exploits/categoryaddon-sql.txt
- http://packetstorm.linuxsecurity.com/0809-exploits/downline-sql.txt
- http://packetstormsecurity.org/0809-exploits/newdownline-sql.txt
- http://secunia.com/advisories/31812
- http://www.securityfocus.com/bid/31169
- http://www.vupen.com/english/advisories/2008/2992
→ the Explorer · watch your stack · NVD