CVE-2009-3304
- EPSS 0.03%
- Veröffentlicht 04.12.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.
CVE-2009-4070
- EPSS 0.41%
- Veröffentlicht 24.11.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.
CVE-2009-4069
- EPSS 0.3%
- Veröffentlicht 24.11.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2009-3303
- EPSS 0.26%
- Veröffentlicht 24.11.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.
CVE-2008-6189
- EPSS 0.17%
- Veröffentlicht 19.02.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php.
CVE-2008-6188
- EPSS 0.42%
- Veröffentlicht 19.02.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.
CVE-2008-6187
- EPSS 0.42%
- Veröffentlicht 19.02.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.
CVE-2008-2381
- EPSS 1.08%
- Veröffentlicht 02.01.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.
CVE-2008-0167
- EPSS 1.07%
- Veröffentlicht 18.05.2008 14:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other i...
CVE-2008-0173
- EPSS 0.61%
- Veröffentlicht 15.01.2008 20:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.