CVE-2008-4895

YourFreeWorld Downline Builder - SQL Injection via tr.php id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2008-4895. PoCs published by Hussin X.

AI-analyzed exploit summary The exploit demonstrates an SQL injection vulnerability in Downline Builder Pro by injecting a UNION-based query to extract database information (user, version, database name). The payload is appended to the 'id' parameter in the 'tr.php' script.

Description

SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Hussin X · textwebappsphp
https://www.exploit-db.com/exploits/32563

The exploit demonstrates an SQL injection vulnerability in Downline Builder Pro by injecting a UNION-based query to extract database information (user, version, database name). The payload is appended to the 'id' parameter in the 'tr.php' script.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Downline Builder Pro
No auth needed
Prerequisites: Access to the vulnerable 'tr.php' endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Hussin X · textwebappsphp
https://www.exploit-db.com/exploits/6935

This is a functional SQL injection exploit for Downline Builder, leveraging a UNION-based attack to extract admin credentials from the 'adminsettings' table. The payload concatenates username and password fields with colons for easy extraction.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Downline Builder (version unspecified)
No auth needed
Prerequisites: Target application with vulnerable 'tr.php' endpoint · Database with 'adminsettings' table containing 'Username' and 'Password' columns
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/6936

This exploit demonstrates a SQL injection vulnerability in Banner Management script via the 'id' parameter in tr.php. The payload uses a UNION-based SQLi to extract database information including user, version, and database name.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Banner Management script (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable tr.php endpoint
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32047
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6935
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32046
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2990
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/49599

Scores

EPSS 0.0105
EPSS Percentile 59.7%

Details

CWE
CWE-89
Status published
Products (1)
yourfreeworld/downline_builder_script
Published Nov 04, 2008
Tracked Since Feb 18, 2026