CVE-2008-6189

GForge 4.5.19 - SQL Injection via Offset Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6189. PoCs published by beford.

AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Gforge <= 4.5.19 by injecting malicious SQL queries into URL parameters like 'offset' and 'pub_sql'. It bypasses magic_quotes_gpc and extracts sensitive data such as user credentials and database version.

Description

SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by beford · textwebappsphp
https://www.exploit-db.com/exploits/6707

The exploit demonstrates SQL injection vulnerabilities in Gforge <= 4.5.19 by injecting malicious SQL queries into URL parameters like 'offset' and 'pub_sql'. It bypasses magic_quotes_gpc and extracts sensitive data such as user credentials and database version.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Gforge <= 4.5.19
No auth needed
Prerequisites: Access to the target Gforge instance
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32217
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45802

Scores

EPSS 0.0232
EPSS Percentile 81.2%

Details

CWE
CWE-89
Status published
Products (1)
gforge/gforge 4.5.19
Published Feb 19, 2009
Tracked Since Feb 18, 2026