VYPR

Gforge

by GForge

CVEs (21)

  • CVE-2008-6189Feb 19, 2009
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php.

  • CVE-2008-6188Feb 19, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.

  • CVE-2008-6187Feb 19, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.

  • CVE-2008-0167May 18, 2008
    risk 0.03cvss epss 0.01

    The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic…

  • CVE-2007-4966Sep 18, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter.

  • CVE-2007-3913Sep 6, 2007
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2005-1752Dec 31, 2005
    risk 0.03cvss epss 0.04

    viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.

  • CVE-2012-1061Feb 14, 2012
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in GForge Advanced Server 6.0.0 and other versions before 6.0.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2009-3304Dec 4, 2009
    risk 0.00cvss epss 0.00

    GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.

  • CVE-2009-4070Nov 24, 2009
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.

  • CVE-2009-4069Nov 24, 2009
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2009-3303Nov 24, 2009
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.

  • CVE-2008-2381Jan 2, 2009
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.

  • CVE-2008-0173Jan 15, 2008
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

  • CVE-2007-3921Nov 8, 2007
    risk 0.00cvss epss 0.00

    gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.

  • CVE-2007-3918Oct 5, 2007
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_hash parameter.

  • CVE-2007-0246May 29, 2007
    risk 0.00cvss epss 0.02

    plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO.

  • CVE-2007-0176Jan 11, 2007
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.

  • CVE-2005-2430Aug 3, 2005
    risk 0.00cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id or (2) group_id parameter to forum.php, (3) project_task_id parameter to task.php, (4) id parameter to detail.php, (5) the text…

  • CVE-2005-2431Aug 3, 2005
    risk 0.00cvss epss 0.01

    The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allows remote attackers to send a large number of messages to arbitrary e-mail addresses (aka mail bomb).

Page 1 of 2