6.4
CVSSv2

CVE-2005-1752

Published: 31/12/2005 Updated: 18/10/2016
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

viewFile.php in the scm component of Gforge prior to 4.0 allows remote malicious users to execute arbitrary commands via shell metacharacters in the file_name parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

gforge gforge 3.1

gforge gforge 3.2

gforge gforge 3.21

gforge gforge 3.3

Exploits

source: wwwsecurityfocuscom/bid/13716/info GForge is affected by a remote command execution vulnerability This issue arises because the application fails to sanitize user-supplied data passed through URI parameters An attacker can supply arbitrary shell commands through the affected parameter to be executed in the context of the affec ...