Vulnerabilities > CVE-2005-0299 - Information Disclosure vulnerability in GForge

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
gforge
nessus

Summary

Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the (1) dir parameter to controller.php or (2) dir_name parameter to controlleroo.php.

Vulnerable Configurations

Part Description Count
Application
Gforge
4

Nessus

  • NASL familyCGI abuses
    NASL idGFORGE_DIR_DISCLOSURE.NASL
    descriptionThe remote host is running GForge, a CVS repository browser written in PHP. The installed version fails to properly sanitize user-supplied data to the
    last seen2020-06-01
    modified2020-06-02
    plugin id16225
    published2005-01-21
    reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/16225
    titleGForge Multiple Script Traversal Arbitrary Directory Listing
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_FE903533FF964C7ABD3E4D40EFA71897.NASL
    descriptionAn STG Security Advisory reports : GForge CVS module made by Dragos Moinescu and another module made by Ronald Petty have a directory traversal vulnerability. [...] malicious attackers can read arbitrary directory lists.
    last seen2020-06-01
    modified2020-06-02
    plugin id19187
    published2005-07-13
    reporterThis script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/19187
    titleFreeBSD : gforge -- directory traversal vulnerability (fe903533-ff96-4c7a-bd3e-4d40efa71897)