Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gforge gforge vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-6188
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and previous versions allows remote malicious users to execute arbitrary SQL commands via the skill_edit[] parameter.
Gforge Gforge 4.6 B2
Gforge Gforge 4.5.16
Gforge Gforge 4.5.19
Gforge Gforge
Gforge Gforge 3.0
Gforge Gforge 3.21
Gforge Gforge 3.3
Gforge Gforge 3.1
Gforge Gforge 3.2
Gforge Gforge 4.5
Gforge Gforge 4.5.11
Gforge Gforge 4.5.14
Gforge Gforge 4.6
1 EDB exploit
NA
CVE-2008-6187
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and previous versions allows remote malicious users to execute arbitrary SQL commands via the release_id parameter.
Gforge Gforge 3.2
Gforge Gforge 3.1
Gforge Gforge 4.5.11
Gforge Gforge 4.5
Gforge Gforge 4.5.16
Gforge Gforge 4.5.14
Gforge Gforge 3.0
Gforge Gforge
Gforge Gforge 3.3
Gforge Gforge 3.21
1 EDB exploit
NA
CVE-2005-1752
viewFile.php in the scm component of Gforge prior to 4.0 allows remote malicious users to execute arbitrary commands via shell metacharacters in the file_name parameter.
Gforge Gforge 3.1
Gforge Gforge 3.2
Gforge Gforge 3.21
Gforge Gforge 3.3
1 EDB exploit
NA
CVE-2005-0299
Directory traversal vulnerability in GForge 3.3 and previous versions allows remote malicious users to list arbitrary directories via a .. (dot dot) in the (1) dir parameter to controller.php or (2) dir_name parameter to controlleroo.php.
Gforge Gforge 3.3
Gforge Gforge 3.2
Gforge Gforge 3.21
Gforge Gforge 3.1
NA
CVE-2009-3303
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote malicious users to inject arbitrary web script or HTML via the helpname parameter.
Gforge Gforge 4.7
Gforge Gforge 4.5.14
Gforge Gforge 4.8.1
NA
CVE-2009-3304
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.
Gforge Gforge 4.5.14
Gforge Gforge 4.8.2
Gforge Gforge 4.7
NA
CVE-2007-3921
gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.
Gforge Gforge 3.1
Gforge Gforge 4.5.14
NA
CVE-2009-4069
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Gforge Gforge 4.5.14
Gforge Gforge 4.7.3
NA
CVE-2009-4070
SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote malicious users to execute arbitrary SQL commands via unknown vectors.
Gforge Gforge 4.7.3
Gforge Gforge 4.5.14
NA
CVE-2008-2381
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote malicious users to execute arbitrary SQL commands via the comments variable.
Gforge Gforge 4.5
Gforge Gforge 4.6
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
cross-site scripting
CVE-2024-5158
XML external entity
CVE-2024-4262
CVE-2024-2036
CVE-2024-4985
CVE-2024-21791
remote attackers
CVE-2023-43208
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »