Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gforge gforge 4.5.14 vulnerabilities and exploits
(subscribe to this query)
294
VMScore
CVE-2009-3304
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.
Gforge Gforge 4.5.14
Gforge Gforge 4.8.2
Gforge Gforge 4.7
383
VMScore
CVE-2009-3303
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote malicious users to inject arbitrary web script or HTML via the helpname parameter.
Gforge Gforge 4.7
Gforge Gforge 4.5.14
Gforge Gforge 4.8.1
383
VMScore
CVE-2009-4069
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Gforge Gforge 4.5.14
Gforge Gforge 4.7.3
294
VMScore
CVE-2007-3921
gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.
Gforge Gforge 3.1
Gforge Gforge 4.5.14
668
VMScore
CVE-2009-4070
SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote malicious users to execute arbitrary SQL commands via unknown vectors.
Gforge Gforge 4.7.3
Gforge Gforge 4.5.14
465
VMScore
CVE-2008-0167
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow malicious users to bypass intended access restrictions or have unspecified other impact in opportunistic c...
Gforge Gforge 4.5.14
1 EDB exploit
755
VMScore
CVE-2008-6187
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and previous versions allows remote malicious users to execute arbitrary SQL commands via the release_id parameter.
Gforge Gforge 3.2
Gforge Gforge 3.1
Gforge Gforge 4.5.11
Gforge Gforge 4.5
Gforge Gforge 4.5.16
Gforge Gforge 4.5.14
Gforge Gforge 3.0
Gforge Gforge
Gforge Gforge 3.3
Gforge Gforge 3.21
1 EDB exploit
755
VMScore
CVE-2008-6188
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and previous versions allows remote malicious users to execute arbitrary SQL commands via the skill_edit[] parameter.
Gforge Gforge 4.6 B2
Gforge Gforge 4.5.16
Gforge Gforge 4.5.19
Gforge Gforge
Gforge Gforge 3.0
Gforge Gforge 3.21
Gforge Gforge 3.3
Gforge Gforge 3.1
Gforge Gforge 3.2
Gforge Gforge 4.5
Gforge Gforge 4.5.11
Gforge Gforge 4.5.14
Gforge Gforge 4.6
1 EDB exploit
605
VMScore
CVE-2007-0246
plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 prior to 20070524, aka gforge-plugin-scmcvs, allows remote malicious users to execute arbitrary commands via shell metacharacters in the PATH_INFO.
Gforge Gforge
755
VMScore
CVE-2007-3913
SQL injection vulnerability in Gforge prior to 3.1 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Gforge Gforge
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »