Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-0173

Опубликовано: 15 янв. 2008
Источник: debian

Описание

SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gforgefixed4.6.99+svn6330-1package

Примечания

  • this is exploitable by unauthenticated users

  • Requires register_globals to be On, unsupported in lenny+sid.

  • In lenny+sid these scripts just don't work, so no security issue.

  • In etch+sarge we support gforge with rg On, unfortunately.

Связанные уязвимости

ubuntu
около 18 лет назад

SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

nvd
около 18 лет назад

SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

github
почти 4 года назад

SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.