PT-2005-1377 · Gforge · Gforge
Published
2005-02-10
·
Updated
2017-07-11
·
CVE-2005-0299
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GForge versions 3.3 and earlier
Description
A directory traversal issue allows remote attackers to list arbitrary directories by using a .. (dot dot) in the
dir parameter to "controller.php" or the dir name parameter to "controlleroo.php".Recommendations
For GForge versions 3.3 and earlier, consider restricting access to the "controller.php" and "controlleroo.php" scripts until a patch is available. As a temporary workaround, avoid using the
dir and dir name parameters in the affected API endpoints.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gforge