CVE-2008-2088

PHP Forge 3.0 beta 2 - SQL Injection via News Module id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-2088. PoCs published by JIKO.

AI-analyzed exploit summary This exploit demonstrates a remote SQL injection vulnerability in Forge 3.0 beta. The PoC manipulates the 'id' parameter in the admin.php script to extract sensitive information from the 'membres' table, including usernames and password hashes.

Description

SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to admin.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by JIKO · textwebappsphp
https://www.exploit-db.com/exploits/5504

This exploit demonstrates a remote SQL injection vulnerability in Forge 3.0 beta. The PoC manipulates the 'id' parameter in the admin.php script to extract sensitive information from the 'membres' table, including usernames and password hashes.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Forge 3.0 beta
No auth needed
Prerequisites: Access to the vulnerable admin.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5504
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42017
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28950
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1386/references

Scores

EPSS 0.0097
EPSS Percentile 57.1%

Details

CWE
CWE-89
Status published
Products (1)
phpforge/php_forge 3.0 beta_2
Published May 06, 2008
Tracked Since Feb 18, 2026