PT-2005-1377 · Gforge · Gforge

Publicado

2005-02-10

·

Atualizado

2017-07-11

·

CVE-2005-0299

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions GForge versions 3.3 and earlier
Description A directory traversal issue allows remote attackers to list arbitrary directories by using a .. (dot dot) in the dir parameter to "controller.php" or the dir name parameter to "controlleroo.php".
Recommendations For GForge versions 3.3 and earlier, consider restricting access to the "controller.php" and "controlleroo.php" scripts until a patch is available. As a temporary workaround, avoid using the dir and dir name parameters in the affected API endpoints.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0299

Produtos afetados

Gforge