Show filters
78 Total Results
Displaying 51-60 of 78
Sort by:
Attacker Value
Unknown
CVE-2009-3304
Disclosure Date: December 04, 2009 (last updated October 04, 2023)
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.
0
Attacker Value
Unknown
CVE-2009-4069
Disclosure Date: November 24, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-3303
Disclosure Date: November 24, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.
0
Attacker Value
Unknown
CVE-2009-4070
Disclosure Date: November 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.
0
Attacker Value
Unknown
CVE-2008-6187
Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.
0
Attacker Value
Unknown
CVE-2008-6189
Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php.
0
Attacker Value
Unknown
CVE-2008-6188
Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.
0
Attacker Value
Unknown
CVE-2008-2381
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.
0
Attacker Value
Unknown
CVE-2008-0167
Disclosure Date: May 18, 2008 (last updated October 04, 2023)
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.
0
Attacker Value
Unknown
CVE-2008-2122
Disclosure Date: May 09, 2008 (last updated February 09, 2024)
IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent server processes that attempt to read data from closed sockets.
0