PT-2005-1377 · Gforge · Gforge

Published

2005-02-10

·

Updated

2017-07-11

·

CVE-2005-0299

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions GForge versions 3.3 and earlier
Description A directory traversal issue allows remote attackers to list arbitrary directories by using a .. (dot dot) in the dir parameter to "controller.php" or the dir name parameter to "controlleroo.php".
Recommendations For GForge versions 3.3 and earlier, consider restricting access to the "controller.php" and "controlleroo.php" scripts until a patch is available. As a temporary workaround, avoid using the dir and dir name parameters in the affected API endpoints.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0299

Affected Products

Gforge