Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Unknown

CVE-2019-10016

Disclosure Date: March 25, 2019 (last updated November 27, 2024)
GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.
0
Attacker Value
Unknown

CVE-2012-1061

Disclosure Date: February 14, 2012 (last updated October 04, 2023)
SQL injection vulnerability in GForge Advanced Server 6.0.0 and other versions before 6.0.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-3304

Disclosure Date: December 04, 2009 (last updated October 04, 2023)
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.
0
Attacker Value
Unknown

CVE-2009-4069

Disclosure Date: November 24, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-3303

Disclosure Date: November 24, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.
0
Attacker Value
Unknown

CVE-2009-4070

Disclosure Date: November 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-6187

Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.
0
Attacker Value
Unknown

CVE-2008-6189

Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php.
0
Attacker Value
Unknown

CVE-2008-6188

Disclosure Date: February 19, 2009 (last updated October 04, 2023)
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.
0
Attacker Value
Unknown

CVE-2008-2381

Disclosure Date: January 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.
0