Gforge / Gforge
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2009-3304 | GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, rel… | LOW | 3.3 | Dec 4, 2009 |
| CVE-2009-4070 | SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors. | HIGH | 7.5 | Nov 24, 2009 |
| CVE-2009-4069 | Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script… | MEDIUM | 4.3 | Nov 24, 2009 |
| CVE-2009-3303 | Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or… | MEDIUM | 4.3 | Nov 24, 2009 |
| CVE-2008-6189 | SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/… | HIGH | 7.5 | Feb 19, 2009 |
| CVE-2008-6188 | SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edi… | HIGH | 7.5 | Feb 19, 2009 |
| CVE-2008-6187 | SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id para… | HIGH | 7.5 | Feb 19, 2009 |
| CVE-2008-2381 | SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary… | HIGH | 7.5 | Jan 2, 2009 |
| CVE-2008-0167 | The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, whi… | MEDIUM | 4.6 | May 18, 2008 |
| CVE-2008-0173 | SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS e… | HIGH | 7.5 | Jan 15, 2008 |
| CVE-2007-3921 | gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files. | LOW | 3.3 | Nov 8, 2007 |
| CVE-2007-3918 | Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_h… | MEDIUM | 4.3 | Oct 5, 2007 |
| CVE-2007-4966 | SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_d… | MEDIUM | 6.8 | Sep 18, 2007 |
| CVE-2007-3913 | SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | HIGH | 7.5 | Sep 6, 2007 |
| CVE-2007-0246 | plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary comman… | MEDIUM | 6.8 | May 29, 2007 |
| CVE-2007-0176 | Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the… | MEDIUM | 6.8 | Jan 11, 2007 |
| CVE-2005-1752 | viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name paramete… | MEDIUM | 6.4 | May 21, 2006 |
| CVE-2005-2431 | The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allo… | MEDIUM | 5.0 | Aug 3, 2005 |
| CVE-2005-2430 | Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id or (2) gro… | MEDIUM | 4.3 | Aug 3, 2005 |
| CVE-2005-0299 | Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the (1) dir parameter t… | MEDIUM | 5.0 | Feb 10, 2005 |
Showing 1 to 20 of 20 CVEs