gforge records
22 published records for vendor gforge.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 11
- With a fix record
- 72.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2007-2298Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a gforge · garennes | High7.5 | — | 2.4% | Apr 26, 2007 |
31Monitor | CVE-2008-6189Proof of concept | SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/igforge · gforge · CWE-89 | High7.5 | — | 2.3% | Feb 19, 2009 |
31Monitor | CVE-2008-0173No exploit | SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parametergforge · gforge · CWE-89 | High7.5 | — | 2.1% | Jan 15, 2008 |
31Monitor | CVE-2007-3913Proof of concept | SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.gforge · gforge · CWE-20 | High7.5 | — | 2.0% | Sep 6, 2007 |
31Monitor | CVE-2009-4070No exploit | SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands vgforge · gforge · CWE-89 | High7.5 | — | 1.7% | Nov 24, 2009 |
30Monitor | CVE-2008-2381No exploit | SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers togforge · gforge · CWE-89 | High7.5 | — | 1.6% | Jan 2, 2009 |
30Monitor | CVE-2008-6188Proof of concept | SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commandgforge · gforge · CWE-89 | High7.5 | — | 1.3% | Feb 19, 2009 |
30Monitor | CVE-2008-6187Proof of concept | SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via gforge · gforge · CWE-89 | High7.5 | — | 1.3% | Feb 19, 2009 |
28Monitor | CVE-2007-0176No exploit | Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web scrigforge · gforge | Medium6.8 | — | 2.0% | Jan 10, 2007 |
28Monitor | CVE-2007-0246No exploit | plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execugforge · gforge | Medium6.8 | — | 1.8% | May 29, 2007 |
27Monitor | CVE-2007-4966Proof of concept | SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commagforge · gforge · CWE-89 | Medium6.8 | — | 1.5% | Sep 18, 2007 |
26Monitor | CVE-2005-1752Proof of concept | viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in thegforge · gforge | Medium6.4 | — | 4.0% | Dec 31, 2005 |
24Monitor | CVE-2019-10016No exploit | GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.gforge · advanced server · CWE-79 | Medium6.1 | — | 0.8% | Mar 24, 2019 |
21Monitor | CVE-2005-0299No exploit | Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a ..gforge · gforge | Medium5.0 | — | 1.7% | May 2, 2005 |
20Monitor | CVE-2005-2431No exploit | The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail gforge · gforge | Medium5.0 | — | 1.3% | Aug 3, 2005 |
18Monitor | CVE-2005-2430No exploit | Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) gforge · gforge | Medium4.3 | — | 2.7% | Aug 3, 2005 |
18Monitor | CVE-2009-4069No exploit | Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject argforge · gforge · CWE-79 | Medium4.3 | — | 1.7% | Nov 24, 2009 |
18Monitor | CVE-2009-3303No exploit | Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbigforge · gforge · CWE-79 | Medium4.3 | — | 1.7% | Nov 24, 2009 |
18Monitor | CVE-2008-0167Proof of concept | The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then wrgforge · gforge · CWE-59 | Medium4.6 | — | 0.7% | May 18, 2008 |
17Monitor | CVE-2007-3918No exploit | Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTMgforge · gforge · CWE-79 | Medium4.3 | — | 1.3% | Oct 5, 2007 |
13Monitor | CVE-2009-3304No exploit | GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' hogforge · gforge · CWE-59 | Low3.3 | — | 0.3% | Dec 4, 2009 |
13Monitor | CVE-2007-3921No exploit | gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.gforge · gforge · CWE-59 | Low3.3 | — | 0.3% | Nov 8, 2007 |
- CVE-2007-229831Monitor
Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a
HighCVSS 7.5Proof of conceptEPSS 2%gforge · garennesApr 26, 2007
- CVE-2008-618931Monitor
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/i
HighCVSS 7.5Proof of conceptEPSS 2%gforge · gforgeFeb 19, 2009
- CVE-2008-017331Monitor
SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameter
HighCVSS 7.5No exploitEPSS 2%gforge · gforgeJan 15, 2008
- CVE-2007-391331Monitor
SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
HighCVSS 7.5Proof of conceptEPSS 2%gforge · gforgeSep 6, 2007
- CVE-2009-407031Monitor
SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands v
HighCVSS 7.5No exploitEPSS 2%gforge · gforgeNov 24, 2009
- CVE-2008-238130Monitor
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to
HighCVSS 7.5No exploitEPSS 2%gforge · gforgeJan 2, 2009
- CVE-2008-618830Monitor
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL command
HighCVSS 7.5Proof of conceptEPSS 1%gforge · gforgeFeb 19, 2009
- CVE-2008-618730Monitor
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%gforge · gforgeFeb 19, 2009
- CVE-2007-017628Monitor
Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web scri
MediumCVSS 6.8No exploitEPSS 2%gforge · gforgeJan 10, 2007
- CVE-2007-024628Monitor
plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execu
MediumCVSS 6.8No exploitEPSS 2%gforge · gforgeMay 29, 2007
- CVE-2007-496627Monitor
SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL comma
MediumCVSS 6.8Proof of conceptEPSS 1%gforge · gforgeSep 18, 2007
- CVE-2005-175226Monitor
viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the
MediumCVSS 6.4Proof of conceptEPSS 4%gforge · gforgeDec 31, 2005
- CVE-2019-1001624Monitor
GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.
MediumCVSS 6.1No exploitEPSS 1%gforge · advanced serverMar 24, 2019
- CVE-2005-029921Monitor
Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a ..
MediumCVSS 5.0No exploitEPSS 2%gforge · gforgeMay 2, 2005
- CVE-2005-243120Monitor
The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail
MediumCVSS 5.0No exploitEPSS 1%gforge · gforgeAug 3, 2005
- CVE-2005-243018Monitor
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1)
MediumCVSS 4.3No exploitEPSS 3%gforge · gforgeAug 3, 2005
- CVE-2009-406918Monitor
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject ar
MediumCVSS 4.3No exploitEPSS 2%gforge · gforgeNov 24, 2009
- CVE-2009-330318Monitor
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbi
MediumCVSS 4.3No exploitEPSS 2%gforge · gforgeNov 24, 2009
- CVE-2008-016718Monitor
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then wr
MediumCVSS 4.6Proof of conceptEPSS 1%gforge · gforgeMay 18, 2008
- CVE-2007-391817Monitor
Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTM
MediumCVSS 4.3No exploitEPSS 1%gforge · gforgeOct 5, 2007
- CVE-2009-330413Monitor
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' ho
LowCVSS 3.3No exploitEPSS 0%gforge · gforgeDec 4, 2009
- CVE-2007-392113Monitor
gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.
LowCVSS 3.3No exploitEPSS 0%gforge · gforgeNov 8, 2007