PT-2005-1377 · Gforge · Gforge
Publicado
2005-02-10
·
Atualizado
2017-07-11
·
CVE-2005-0299
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GForge versions 3.3 and earlier
Description
A directory traversal issue allows remote attackers to list arbitrary directories by using a .. (dot dot) in the
dir parameter to "controller.php" or the dir name parameter to "controlleroo.php".Recommendations
For GForge versions 3.3 and earlier, consider restricting access to the "controller.php" and "controlleroo.php" scripts until a patch is available. As a temporary workaround, avoid using the
dir and dir name parameters in the affected API endpoints.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gforge