Unrated severityNVD Advisory· Published Feb 19, 2009· Updated Apr 23, 2026
CVE-2008-6188
CVE-2008-6188
Description
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.
Affected products
13cpe:2.3:a:gforge:gforge:*:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:gforge:gforge:*:*:*:*:*:*:*:*range: <=4.6rc1
- cpe:2.3:a:gforge:gforge:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:gforge:gforge:3.1:*:*:*:*:*:*:*
- cpe:2.3:a:gforge:gforge:3.2:*:*:*:*:*:*:*
- cpe:2.3:a:gforge:gforge:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:gforge:gforge:3.21:*:*:*:*:*:*:*
- cpe:2.3:a:gforge:gforge:4.5:*:*:*:*:*:*:*
- cpe:2.3:a:gforge:gforge:4.5.11:*:*:*:*:*:*:*
- cpe:2.3:a:gforge:gforge:4.5.14:*:*:*:*:*:*:*
- cpe:2.3:a:gforge:gforge:4.5.16:*:*:*:*:*:*:*
- cpe:2.3:a:gforge:gforge:4.5.19:*:*:*:*:*:*:*
- cpe:2.3:a:gforge:gforge:4.6:*:*:*:*:*:*:*
- cpe:2.3:a:gforge:gforge:4.6_b2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- gforge.org/tracker/index.phpnvdExploitVendor Advisory
- www.securityfocus.com/bid/31674nvdExploit
- secunia.com/advisories/32217nvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/48851nvd
- www.exploit-db.com/exploits/6708nvd
News mentions
0No linked articles in our index yet.