Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-0173

Опубликовано: 15 янв. 2008
Источник: debian
EPSS Низкий

Описание

SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gforgefixed4.6.99+svn6330-1package

Примечания

  • this is exploitable by unauthenticated users

  • Requires register_globals to be On, unsupported in lenny+sid.

  • In lenny+sid these scripts just don't work, so no security issue.

  • In etch+sarge we support gforge with rg On, unfortunately.

EPSS

Процентиль: 69%
0.00605
Низкий

Связанные уязвимости

ubuntu
почти 18 лет назад

SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

nvd
почти 18 лет назад

SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

github
больше 3 лет назад

SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

EPSS

Процентиль: 69%
0.00605
Низкий