Vulnerabilities > CVE-2005-1752 - Remote Arbitrary Command Execution vulnerability in GForge

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
gforge
exploit available

Summary

viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.

Vulnerable Configurations

Part Description Count
Application
Gforge
4

Exploit-Db

descriptionGForge 3.x Remote Arbitrary Command Execution Vulnerability. CVE-2005-1752. Webapps exploit for php platform
idEDB-ID:25693
last seen2016-02-03
modified2005-05-24
published2005-05-24
reporterFilippo Spike Morelli
sourcehttps://www.exploit-db.com/download/25693/
titleGForge 3.x - Remote Arbitrary Command Execution Vulnerability