Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Unknown
CVE-2019-10016
Disclosure Date: March 25, 2019 (last updated November 27, 2024)
GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.
0
Attacker Value
Unknown
CVE-2012-1061
Disclosure Date: February 14, 2012 (last updated October 04, 2023)
SQL injection vulnerability in GForge Advanced Server 6.0.0 and other versions before 6.0.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-3304
Disclosure Date: December 04, 2009 (last updated October 04, 2023)
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.
0
Attacker Value
Unknown
CVE-2009-4069
Disclosure Date: November 24, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-3303
Disclosure Date: November 24, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.
0
Attacker Value
Unknown
CVE-2009-4070
Disclosure Date: November 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.
0
Attacker Value
Unknown
CVE-2008-6187
Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.
0
Attacker Value
Unknown
CVE-2008-6189
Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php.
0
Attacker Value
Unknown
CVE-2008-6188
Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.
0
Attacker Value
Unknown
CVE-2008-2381
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.
0