GForge <= 4.5 Multiple Script XSS

This script is Copyright (C) 2005-2014 Tenable Network Security, Inc.


Synopsis :

The remote web server contains a PHP script that is affected by
multiple cross-site scripting vulnerabilities.

Description :

The remote host is running GForge, an open source software development
collaborative toolset using PHP and PostgreSQL.

The installed version of GForge on the remote host fails to properly
sanitize user-supplied input to several parameters / scripts before
using it in dynamically-generated pages. An attacker can exploit
these flaws to launch cross-site scripting attacks against the
affected application.

See also :

http://www.securityfocus.com/archive/1/406723/30/0/threaded

Solution :

Unknown at this time.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 4.3
(CVSS2#E:H/RL:U/RC:ND)
Public Exploit Available : true

Family: CGI abuses : XSS

Nessus Plugin ID: 19314 (gforge_45.nasl)

Bugtraq ID: 14405

CVE ID: CVE-2005-2430