Vulnerabilities > Gforge > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-03-25 CVE-2019-10016 Cross-site Scripting vulnerability in Gforge Advanced Server 6.4.4
GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.
network
gforge CWE-79
4.3
2009-11-24 CVE-2009-4069 Cross-Site Scripting vulnerability in Gforge 4.5.14/4.7.3
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
gforge CWE-79
4.3
2009-11-24 CVE-2009-3303 Cross-Site Scripting vulnerability in Gforge 4.5.14/4.7/4.8.1
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.
network
gforge CWE-79
4.3
2008-05-18 CVE-2008-0167 Link Following vulnerability in Gforge 4.5.14
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.
local
low complexity
debian gforge CWE-59
4.6
2007-10-05 CVE-2007-3918 Cross-Site Scripting vulnerability in Gforge 4.6B2
Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_hash parameter.
network
gforge CWE-79
4.3
2007-09-18 CVE-2007-4966 SQL Injection vulnerability in Gforge
SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter.
network
gforge CWE-89
6.8
2007-05-29 CVE-2007-0246 Remote Arbitrary Command Execution vulnerability in GForge
plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO.
network
gforge
6.8
2007-01-11 CVE-2007-0176 Cross-Site Scripting vulnerability in Gforge 4.5.11
Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.
network
gforge
6.8
2005-12-31 CVE-2005-1752 Remote Arbitrary Command Execution vulnerability in GForge
viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.
network
low complexity
gforge
6.4
2005-08-03 CVE-2005-2431 Remote Security vulnerability in Gforge 4.5
The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allows remote attackers to send a large number of messages to arbitrary e-mail addresses (aka mail bomb).
network
low complexity
gforge
5.0