GForge Multiple Unspecified SQL Injection Vulnerabilities
BID:27266
Info
GForge Multiple Unspecified SQL Injection Vulnerabilities
| Bugtraq ID: | 27266 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0173 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 13 2008 12:00AM |
| Updated: | Jan 15 2008 02:28PM |
| Credit: | These issues were reported in a Debian advisory. |
| Vulnerable: |
GForge GForge 4.5.14 GForge GForge 3.1 GForge GForge 4.6 |
| Not Vulnerable: | |
Discussion
GForge Multiple Unspecified SQL Injection Vulnerabilities
GForge is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in SQL queries.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
GForge is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in SQL queries.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
GForge Multiple Unspecified SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
GForge Multiple Unspecified SQL Injection Vulnerabilities
Solution:
Please see the references for more information.
Solution:
Please see the references for more information.