gforge kayıtları
gforge üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %72,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-20 Improper Input Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2007-2298Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a gforge · garennes | Yüksek7,5 | — | %2,4 | 26 Nis 2007 |
31İzleyin | CVE-2008-6189Kavram kanıtı | SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/igforge · gforge · CWE-89 | Yüksek7,5 | — | %2,3 | 19 Şub 2009 |
31İzleyin | CVE-2008-0173İstismar yok | SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parametergforge · gforge · CWE-89 | Yüksek7,5 | — | %2,1 | 15 Oca 2008 |
31İzleyin | CVE-2007-3913Kavram kanıtı | SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.gforge · gforge · CWE-20 | Yüksek7,5 | — | %2,0 | 6 Eyl 2007 |
31İzleyin | CVE-2009-4070İstismar yok | SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands vgforge · gforge · CWE-89 | Yüksek7,5 | — | %1,7 | 24 Kas 2009 |
30İzleyin | CVE-2008-2381İstismar yok | SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers togforge · gforge · CWE-89 | Yüksek7,5 | — | %1,6 | 2 Oca 2009 |
30İzleyin | CVE-2008-6188Kavram kanıtı | SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commandgforge · gforge · CWE-89 | Yüksek7,5 | — | %1,3 | 19 Şub 2009 |
30İzleyin | CVE-2008-6187Kavram kanıtı | SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via gforge · gforge · CWE-89 | Yüksek7,5 | — | %1,3 | 19 Şub 2009 |
28İzleyin | CVE-2007-0176İstismar yok | Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web scrigforge · gforge | Orta6,8 | — | %2,0 | 10 Oca 2007 |
28İzleyin | CVE-2007-0246İstismar yok | plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execugforge · gforge | Orta6,8 | — | %1,8 | 29 May 2007 |
27İzleyin | CVE-2007-4966Kavram kanıtı | SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commagforge · gforge · CWE-89 | Orta6,8 | — | %1,5 | 18 Eyl 2007 |
26İzleyin | CVE-2005-1752Kavram kanıtı | viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in thegforge · gforge | Orta6,4 | — | %4,0 | 31 Ara 2005 |
24İzleyin | CVE-2019-10016İstismar yok | GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.gforge · advanced server · CWE-79 | Orta6,1 | — | %0,8 | 24 Mar 2019 |
21İzleyin | CVE-2005-0299İstismar yok | Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a ..gforge · gforge | Orta5,0 | — | %1,7 | 2 May 2005 |
20İzleyin | CVE-2005-2431İstismar yok | The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail gforge · gforge | Orta5,0 | — | %1,3 | 3 Ağu 2005 |
18İzleyin | CVE-2005-2430İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) gforge · gforge | Orta4,3 | — | %2,7 | 3 Ağu 2005 |
18İzleyin | CVE-2009-4069İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject argforge · gforge · CWE-79 | Orta4,3 | — | %1,7 | 24 Kas 2009 |
18İzleyin | CVE-2009-3303İstismar yok | Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbigforge · gforge · CWE-79 | Orta4,3 | — | %1,7 | 24 Kas 2009 |
18İzleyin | CVE-2008-0167Kavram kanıtı | The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then wrgforge · gforge · CWE-59 | Orta4,6 | — | %0,7 | 18 May 2008 |
17İzleyin | CVE-2007-3918İstismar yok | Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTMgforge · gforge · CWE-79 | Orta4,3 | — | %1,3 | 5 Eki 2007 |
13İzleyin | CVE-2009-3304İstismar yok | GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' hogforge · gforge · CWE-59 | Düşük3,3 | — | %0,3 | 4 Ara 2009 |
13İzleyin | CVE-2007-3921İstismar yok | gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.gforge · gforge · CWE-59 | Düşük3,3 | — | %0,3 | 8 Kas 2007 |
- CVE-2007-229831İzleyin
Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a
YüksekCVSS 7,5Kavram kanıtıEPSS %2gforge · garennes26 Nis 2007
- CVE-2008-618931İzleyin
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/i
YüksekCVSS 7,5Kavram kanıtıEPSS %2gforge · gforge19 Şub 2009
- CVE-2008-017331İzleyin
SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameter
YüksekCVSS 7,5İstismar yokEPSS %2gforge · gforge15 Oca 2008
- CVE-2007-391331İzleyin
SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
YüksekCVSS 7,5Kavram kanıtıEPSS %2gforge · gforge6 Eyl 2007
- CVE-2009-407031İzleyin
SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands v
YüksekCVSS 7,5İstismar yokEPSS %2gforge · gforge24 Kas 2009
- CVE-2008-238130İzleyin
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to
YüksekCVSS 7,5İstismar yokEPSS %2gforge · gforge2 Oca 2009
- CVE-2008-618830İzleyin
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL command
YüksekCVSS 7,5Kavram kanıtıEPSS %1gforge · gforge19 Şub 2009
- CVE-2008-618730İzleyin
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via
YüksekCVSS 7,5Kavram kanıtıEPSS %1gforge · gforge19 Şub 2009
- CVE-2007-017628İzleyin
Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web scri
OrtaCVSS 6,8İstismar yokEPSS %2gforge · gforge10 Oca 2007
- CVE-2007-024628İzleyin
plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execu
OrtaCVSS 6,8İstismar yokEPSS %2gforge · gforge29 May 2007
- CVE-2007-496627İzleyin
SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL comma
OrtaCVSS 6,8Kavram kanıtıEPSS %1gforge · gforge18 Eyl 2007
- CVE-2005-175226İzleyin
viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the
OrtaCVSS 6,4Kavram kanıtıEPSS %4gforge · gforge31 Ara 2005
- CVE-2019-1001624İzleyin
GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.
OrtaCVSS 6,1İstismar yokEPSS %1gforge · advanced server24 Mar 2019
- CVE-2005-029921İzleyin
Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a ..
OrtaCVSS 5,0İstismar yokEPSS %2gforge · gforge2 May 2005
- CVE-2005-243120İzleyin
The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail
OrtaCVSS 5,0İstismar yokEPSS %1gforge · gforge3 Ağu 2005
- CVE-2005-243018İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1)
OrtaCVSS 4,3İstismar yokEPSS %3gforge · gforge3 Ağu 2005
- CVE-2009-406918İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject ar
OrtaCVSS 4,3İstismar yokEPSS %2gforge · gforge24 Kas 2009
- CVE-2009-330318İzleyin
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbi
OrtaCVSS 4,3İstismar yokEPSS %2gforge · gforge24 Kas 2009
- CVE-2008-016718İzleyin
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then wr
OrtaCVSS 4,6Kavram kanıtıEPSS %1gforge · gforge18 May 2008
- CVE-2007-391817İzleyin
Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTM
OrtaCVSS 4,3İstismar yokEPSS %1gforge · gforge5 Eki 2007
- CVE-2009-330413İzleyin
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' ho
DüşükCVSS 3,3İstismar yokEPSS %0gforge · gforge4 Ara 2009
- CVE-2007-392113İzleyin
gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.
DüşükCVSS 3,3İstismar yokEPSS %0gforge · gforge8 Kas 2007