---
cve: "CVE-2008-4627"
severity: "HIGH"
cvss: 7.5
epss: "18.8%"
vendor: "Generic Security"
kev: false
exploited: false
published: "2008-10-21 01:18:02"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-10T01:13:31+02:00"
---

# CVE-2008-4627

> 7.5 HIGH

## Beschreibung

SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execute arbitrary SQL commands via the itemID parameter in the RGalleryImageWrapper page in index.php.

## CVSS-Vektor

```
AV:N/AC:L/Au:N/C:P/I:P/A:P
```

## Exploit-Evidenz

- [EDB-6790 — WBB Plugin rGallery 1.09 - 'itemID' Blind SQL Injection](https://www.exploit-db.com/exploits/6790) ✅

## Referenzen

- <http://secunia.com/advisories/32323>
- <http://securityreason.com/securityalert/4443>
- <http://www.securityfocus.com/bid/31820>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/45966>
- <https://www.exploit-db.com/exploits/6790>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2008-4627) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
