7.5
CVSSv2

CVE-2008-0173

Published: 15/01/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Gforge 4.6.99 and previous versions allows remote malicious users to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gforge gforge

Vendor Advisories

It was discovered that Gforge, a collaborative development tool, did not properly sanitise some CGI parameters, allowing SQL injection in scripts related to RSS exports For the old stable distribution (sarge), this problem has been fixed in version 31-31sarge5 For the stable distribution (etch), this problem has been fixed in version 4514- ...