LWN.net Logo

gforge: multiple vulnerabilities

Package(s):gforge CVE #(s):
Created:June 24, 2009 Updated:June 24, 2009
Description: Laurent Almeras and Guillaume Smet have discovered a possible SQL injection vulnerability and cross-site scripting vulnerabilities in gforge, a collaborative development tool. Due to insufficient input sanitising, it was possible to inject arbitrary SQL statements and use several parameters to conduct cross-site scripting attacks.
Alerts:
Debian DSA-1818-1 2009-06-18

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds