Gforge Unspecified SQL Injection Vulnerability
BID:25585
Info
Gforge Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 25585 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3913 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2007 12:00AM |
| Updated: | Sep 10 2007 05:01PM |
| Credit: | Sumit I. Siddharth is credited with the discovery of this vulnerability. |
| Vulnerable: |
GForge GForge 3.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Gforge Unspecified SQL Injection Vulnerability
Gforge is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Gforge 3.1 is vulnerable; other versions may also be affected.
Gforge is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Gforge 3.1 is vulnerable; other versions may also be affected.
Exploit / POC
Gforge Unspecified SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Gforge Unspecified SQL Injection Vulnerability
Solution:
Please see the referenced advisories for more information.
Solution:
Please see the referenced advisories for more information.