Записи gforge
22 опубликованных записей вендора gforge.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 72,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-20 Improper Input Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2007-2298Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a gforge · garennes | Высокая7,5 | — | 2,4 % | 26 апр. 2007 г. |
31Наблюдать | CVE-2008-6189Proof of concept | SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/igforge · gforge · CWE-89 | Высокая7,5 | — | 2,3 % | 19 февр. 2009 г. |
31Наблюдать | CVE-2008-0173Эксплойта нет | SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parametergforge · gforge · CWE-89 | Высокая7,5 | — | 2,1 % | 15 янв. 2008 г. |
31Наблюдать | CVE-2007-3913Proof of concept | SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.gforge · gforge · CWE-20 | Высокая7,5 | — | 2,0 % | 6 сент. 2007 г. |
31Наблюдать | CVE-2009-4070Эксплойта нет | SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands vgforge · gforge · CWE-89 | Высокая7,5 | — | 1,7 % | 24 нояб. 2009 г. |
30Наблюдать | CVE-2008-2381Эксплойта нет | SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers togforge · gforge · CWE-89 | Высокая7,5 | — | 1,6 % | 2 янв. 2009 г. |
30Наблюдать | CVE-2008-6188Proof of concept | SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commandgforge · gforge · CWE-89 | Высокая7,5 | — | 1,3 % | 19 февр. 2009 г. |
30Наблюдать | CVE-2008-6187Proof of concept | SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via gforge · gforge · CWE-89 | Высокая7,5 | — | 1,3 % | 19 февр. 2009 г. |
28Наблюдать | CVE-2007-0176Эксплойта нет | Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web scrigforge · gforge | Средняя6,8 | — | 2,0 % | 10 янв. 2007 г. |
28Наблюдать | CVE-2007-0246Эксплойта нет | plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execugforge · gforge | Средняя6,8 | — | 1,8 % | 29 мая 2007 г. |
27Наблюдать | CVE-2007-4966Proof of concept | SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commagforge · gforge · CWE-89 | Средняя6,8 | — | 1,5 % | 18 сент. 2007 г. |
26Наблюдать | CVE-2005-1752Proof of concept | viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in thegforge · gforge | Средняя6,4 | — | 4,0 % | 31 дек. 2005 г. |
24Наблюдать | CVE-2019-10016Эксплойта нет | GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.gforge · advanced server · CWE-79 | Средняя6,1 | — | 0,8 % | 24 мар. 2019 г. |
21Наблюдать | CVE-2005-0299Эксплойта нет | Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a ..gforge · gforge | Средняя5,0 | — | 1,7 % | 2 мая 2005 г. |
20Наблюдать | CVE-2005-2431Эксплойта нет | The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail gforge · gforge | Средняя5,0 | — | 1,3 % | 3 авг. 2005 г. |
18Наблюдать | CVE-2005-2430Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) gforge · gforge | Средняя4,3 | — | 2,7 % | 3 авг. 2005 г. |
18Наблюдать | CVE-2009-4069Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject argforge · gforge · CWE-79 | Средняя4,3 | — | 1,7 % | 24 нояб. 2009 г. |
18Наблюдать | CVE-2009-3303Эксплойта нет | Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbigforge · gforge · CWE-79 | Средняя4,3 | — | 1,7 % | 24 нояб. 2009 г. |
18Наблюдать | CVE-2008-0167Proof of concept | The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then wrgforge · gforge · CWE-59 | Средняя4,6 | — | 0,7 % | 18 мая 2008 г. |
17Наблюдать | CVE-2007-3918Эксплойта нет | Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTMgforge · gforge · CWE-79 | Средняя4,3 | — | 1,3 % | 5 окт. 2007 г. |
13Наблюдать | CVE-2009-3304Эксплойта нет | GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' hogforge · gforge · CWE-59 | Низкая3,3 | — | 0,3 % | 4 дек. 2009 г. |
13Наблюдать | CVE-2007-3921Эксплойта нет | gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.gforge · gforge · CWE-59 | Низкая3,3 | — | 0,3 % | 8 нояб. 2007 г. |
- CVE-2007-229831Наблюдать
Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %gforge · garennes26 апр. 2007 г.
- CVE-2008-618931Наблюдать
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/i
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %gforge · gforge19 февр. 2009 г.
- CVE-2008-017331Наблюдать
SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameter
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %gforge · gforge15 янв. 2008 г.
- CVE-2007-391331Наблюдать
SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %gforge · gforge6 сент. 2007 г.
- CVE-2009-407031Наблюдать
SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands v
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %gforge · gforge24 нояб. 2009 г.
- CVE-2008-238130Наблюдать
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %gforge · gforge2 янв. 2009 г.
- CVE-2008-618830Наблюдать
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL command
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %gforge · gforge19 февр. 2009 г.
- CVE-2008-618730Наблюдать
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %gforge · gforge19 февр. 2009 г.
- CVE-2007-017628Наблюдать
Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web scri
СредняяCVSS 6,8Эксплойта нетEPSS 2 %gforge · gforge10 янв. 2007 г.
- CVE-2007-024628Наблюдать
plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execu
СредняяCVSS 6,8Эксплойта нетEPSS 2 %gforge · gforge29 мая 2007 г.
- CVE-2007-496627Наблюдать
SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL comma
СредняяCVSS 6,8Proof of conceptEPSS 1 %gforge · gforge18 сент. 2007 г.
- CVE-2005-175226Наблюдать
viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the
СредняяCVSS 6,4Proof of conceptEPSS 4 %gforge · gforge31 дек. 2005 г.
- CVE-2019-1001624Наблюдать
GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %gforge · advanced server24 мар. 2019 г.
- CVE-2005-029921Наблюдать
Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a ..
СредняяCVSS 5,0Эксплойта нетEPSS 2 %gforge · gforge2 мая 2005 г.
- CVE-2005-243120Наблюдать
The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail
СредняяCVSS 5,0Эксплойта нетEPSS 1 %gforge · gforge3 авг. 2005 г.
- CVE-2005-243018Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1)
СредняяCVSS 4,3Эксплойта нетEPSS 3 %gforge · gforge3 авг. 2005 г.
- CVE-2009-406918Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject ar
СредняяCVSS 4,3Эксплойта нетEPSS 2 %gforge · gforge24 нояб. 2009 г.
- CVE-2009-330318Наблюдать
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbi
СредняяCVSS 4,3Эксплойта нетEPSS 2 %gforge · gforge24 нояб. 2009 г.
- CVE-2008-016718Наблюдать
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then wr
СредняяCVSS 4,6Proof of conceptEPSS 1 %gforge · gforge18 мая 2008 г.
- CVE-2007-391817Наблюдать
Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTM
СредняяCVSS 4,3Эксплойта нетEPSS 1 %gforge · gforge5 окт. 2007 г.
- CVE-2009-330413Наблюдать
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' ho
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %gforge · gforge4 дек. 2009 г.
- CVE-2007-392113Наблюдать
gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %gforge · gforge8 нояб. 2007 г.