CVE-2008-4178
Summary
| CVE | CVE-2008-4178 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-09-23 15:25:42 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and Downline Goldmine Builder allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Downline Goldmine | Builder | All | All | All | All |
| Application | Downline Goldmine | Builder | special_category_addon | All | All | All |
| Application | Downline Goldmine | Builder | unknown | unknown | pro | All |
| Application | Downline Goldmine | New Addon | All | All | All | All |
| Application | Downline Goldmine | New Addon | pro | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Downline Goldmine Builder "id" SQL Injection - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| DownlineGoldmine Multiple Products 'tr.php' SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Downline Goldmine paidversion - SQL Injection - PHP webapps Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Files ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.org | Exploit |
| Downline Goldmine newdownlinebuilder - SQL Injection - PHP webapps Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| packetstorm.linuxsecurity.com/0809-exploits/categoryaddon-sql.txt | af854a3a-2127-422b-91ae-364da2661108 | packetstorm.linuxsecurity.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Downline Goldmine Builder - SQL Injection - PHP webapps Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| packetstorm.linuxsecurity.com/0809-exploits/downline-sql.txt | af854a3a-2127-422b-91ae-364da2661108 | packetstorm.linuxsecurity.com | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Downline Goldmine Category Addon - SQL Injection - PHP webapps Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.