CVE-2007-0246: Medium severity GForge vulnerability
Published May 29, 2007
·Updated
plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATHINFO.
Affected Software
1 affected component
GForge<=4.5.16
Remediation
Patch Available
Patch Available
Event History
May 29, 2007
CVE Published
09:30 PM
May 30, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0246?
CVE-2007-0246 has a high severity rating due to its ability to allow remote code execution.
2
How do I fix CVE-2007-0246?
To fix CVE-2007-0246, upgrade to GForge version 4.5.16 or later released after May 24, 2007.
3
What does CVE-2007-0246 affect?
CVE-2007-0246 specifically affects versions of GForge prior to 4.5.16 released on May 24, 2007.
4
What type of vulnerability is CVE-2007-0246?
CVE-2007-0246 is a remote command execution vulnerability due to improper handling of input in the CVSWeb CGI.
5
Can CVE-2007-0246 impact my system if I am using GForge 4.5.16 or later?
No, if you are using GForge 4.5.16 or later, your system is not impacted by CVE-2007-0246.