Show filters
78 Total Results
Displaying 51-60 of 78
Sort by:
Attacker Value
Unknown

CVE-2009-3304

Disclosure Date: December 04, 2009 (last updated October 04, 2023)
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.
0
Attacker Value
Unknown

CVE-2009-4069

Disclosure Date: November 24, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-3303

Disclosure Date: November 24, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.
0
Attacker Value
Unknown

CVE-2009-4070

Disclosure Date: November 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-6187

Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.
0
Attacker Value
Unknown

CVE-2008-6189

Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php.
0
Attacker Value
Unknown

CVE-2008-6188

Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.
0
Attacker Value
Unknown

CVE-2008-2381

Disclosure Date: January 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.
0
Attacker Value
Unknown

CVE-2008-0167

Disclosure Date: May 18, 2008 (last updated October 04, 2023)
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.
0
Attacker Value
Unknown

CVE-2008-2122

Disclosure Date: May 09, 2008 (last updated February 09, 2024)
IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent server processes that attempt to read data from closed sockets.