CVE-2005-1752

Gforge <4.0 - Command Injection

Title source: llm
STIX 2.1

Description

viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Filippo Spike Morelli · textwebappsphp
https://www.exploit-db.com/exploits/25693

References (3)

Core 3
Core References
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13716
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/13845
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111695779919830&w=2

Scores

EPSS 0.1485
EPSS Percentile 94.6%

Details

Status published
Products (4)
gforge/gforge 3.1
gforge/gforge 3.2
gforge/gforge 3.3
gforge/gforge 3.21
Published Dec 31, 2005
Tracked Since Feb 18, 2026