Vulnerabilities > Gforge > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-03-25 | CVE-2019-10016 | Cross-site Scripting vulnerability in Gforge Advanced Server 6.4.4 GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring. | 4.3 |
2009-11-24 | CVE-2009-4069 | Cross-Site Scripting vulnerability in Gforge 4.5.14/4.7.3 Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 4.3 |
2009-11-24 | CVE-2009-3303 | Cross-Site Scripting vulnerability in Gforge 4.5.14/4.7/4.8.1 Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter. | 4.3 |
2008-05-18 | CVE-2008-0167 | Link Following vulnerability in Gforge 4.5.14 The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances. | 4.6 |
2007-10-05 | CVE-2007-3918 | Cross-Site Scripting vulnerability in Gforge 4.6B2 Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_hash parameter. | 4.3 |
2007-09-18 | CVE-2007-4966 | SQL Injection vulnerability in Gforge SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter. | 6.8 |
2007-05-29 | CVE-2007-0246 | Remote Arbitrary Command Execution vulnerability in GForge plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO. network gforge | 6.8 |
2007-01-11 | CVE-2007-0176 | Cross-Site Scripting vulnerability in Gforge 4.5.11 Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter. network gforge | 6.8 |
2005-12-31 | CVE-2005-1752 | Remote Arbitrary Command Execution vulnerability in GForge viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter. | 6.4 |
2005-08-03 | CVE-2005-2431 | Remote Security vulnerability in Gforge 4.5 The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allows remote attackers to send a large number of messages to arbitrary e-mail addresses (aka mail bomb). | 5.0 |