VYPR
Vendor

GForge

GForge is a commercial service originally based on the Alexandria software behind SourceForge, a web-based project management and collaboration system which was licensed under the GPL. Open source versions of the GForge code were released from 2002 to 2009, at which point the company behind GForge focused on their proprietary service offering which provides project hosting, version control, code reviews, ticketing, release management, continuous integration and messaging.

Founded 2006
Products
4
CVEs
22
Across products
24
Status
Private

Products

4

Recent CVEs

22
View all 22 CVEs →
  • CVE-2008-6189Feb 19, 2009
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php.

  • CVE-2008-6188Feb 19, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.

  • CVE-2008-6187Feb 19, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.

  • CVE-2008-0167May 18, 2008
    risk 0.03cvss epss 0.01

    The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic…

  • CVE-2007-4966Sep 18, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter.

  • CVE-2007-3913Sep 6, 2007
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2007-2298Apr 26, 2007
    risk 0.03cvss epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoire_config parameter to index.php in (1) cpe/, (2) direction/, or (3) professeurs/.

  • CVE-2005-1752Dec 31, 2005
    risk 0.03cvss epss 0.04

    viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.

  • CVE-2012-1061Feb 14, 2012
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in GForge Advanced Server 6.0.0 and other versions before 6.0.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2009-3304Dec 4, 2009
    risk 0.00cvss epss 0.00

    GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.

  • CVE-2009-4070Nov 24, 2009
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.

  • CVE-2009-4069Nov 24, 2009
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2009-3303Nov 24, 2009
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.

  • CVE-2008-2381Jan 2, 2009
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.

  • CVE-2008-0173Jan 15, 2008
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

  • CVE-2007-3921Nov 8, 2007
    risk 0.00cvss epss 0.00

    gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.

  • CVE-2007-3918Oct 5, 2007
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_hash parameter.

  • CVE-2007-0246May 29, 2007
    risk 0.00cvss epss 0.02

    plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO.

  • CVE-2007-0176Jan 11, 2007
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.

  • CVE-2005-2430Aug 3, 2005
    risk 0.00cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id or (2) group_id parameter to forum.php, (3) project_task_id parameter to task.php, (4) id parameter to detail.php, (5) the text…