Vulnerabilities > Gforge > Gforge > 4.5.14

DATE CVE VULNERABILITY TITLE RISK
2009-12-04 CVE-2009-3304 Link Following vulnerability in Gforge 4.5.14/4.7/4.8.2
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.
local
gforge CWE-59
3.3
2009-11-24 CVE-2009-4070 SQL Injection vulnerability in Gforge 4.5.14/4.7.3
SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.
network
low complexity
gforge CWE-89
7.5
2009-11-24 CVE-2009-4069 Cross-Site Scripting vulnerability in Gforge 4.5.14/4.7.3
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
gforge CWE-79
4.3
2009-11-24 CVE-2009-3303 Cross-Site Scripting vulnerability in Gforge 4.5.14/4.7/4.8.1
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.
network
gforge CWE-79
4.3
2009-02-19 CVE-2008-6188 SQL Injection vulnerability in Gforge
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.
network
low complexity
gforge CWE-89
7.5
2009-02-19 CVE-2008-6187 SQL Injection vulnerability in Gforge
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.
network
low complexity
gforge CWE-89
7.5
2008-05-18 CVE-2008-0167 Link Following vulnerability in Gforge 4.5.14
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.
local
low complexity
debian gforge CWE-59
4.6
2007-11-08 CVE-2007-3921 Link Following vulnerability in Gforge 3.1/4.5.14
gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.
local
gforge CWE-59
3.3