CVE-2008-6032

WSN Links Free 4.0.34P - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6032. PoCs published by Stack.

AI-analyzed exploit summary This exploit demonstrates a blind SQL injection vulnerability in WSN Links Free 4.0.34P. It includes a PHP script to extract the MySQL user by brute-forcing character by character using regex and LIKE conditions.

Description

SQL injection vulnerability in comments.php in WSN Links Free 4.0.34P allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stack · phpwebappsphp
https://www.exploit-db.com/exploits/6529

This exploit demonstrates a blind SQL injection vulnerability in WSN Links Free 4.0.34P. It includes a PHP script to extract the MySQL user by brute-forcing character by character using regex and LIKE conditions.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: WSN Links Free 4.0.34P
No auth needed
Prerequisites: A vulnerable instance of WSN Links Free 4.0.34P · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/48534
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6529
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2656

Scores

EPSS 0.0100
EPSS Percentile 58.1%

Details

CWE
CWE-89
Status published
Products (1)
wsn/links 4.0.34p
Published Feb 03, 2009
Tracked Since Feb 18, 2026