LWN.net Logo

gforge: SQL injection

Package(s):gforge CVE #(s):CVE-2008-0173
Created:January 14, 2008 Updated:January 16, 2008
Description:

From the Debian advisory:

It was discovered that Gforge, a collaborative development tool, did not properly sanitise some CGI parameters, allowing SQL injection in scripts related to RSS exports.

Alerts:
Debian DSA-1459-1 2008-01-13

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds