Vulnerability Name:

CVE-2009-3303 (CCN-54368)

Assigned:2009-11-20
Published:2009-11-20
Updated:2009-11-24
Summary:Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2009-3303

Source: CCN
Type: GForge Web site
GForge Collaborative Development Environment

Source: SECUNIA
Type: Vendor Advisory
37450

Source: CONFIRM
Type: Patch
http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch12.diff.gz

Source: DEBIAN
Type: Patch
DSA-1937

Source: DEBIAN
Type: DSA-1937
gforge -- insufficient input sanitising

Source: CCN
Type: OSVDB ID: 60485
GForge help/tracker.php helpname Parameter XSS

Source: BID
Type: Patch
37088

Source: CCN
Type: BID-37088
GForge 'helpname' Parameter Cross Site Scripting Vulnerability

Source: XF
Type: UNKNOWN
gforge-helpname-xss(54368)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gforge:gforge:4.5.14:*:*:*:*:*:*:*
  • OR cpe:/a:gforge:gforge:4.7:rc2:*:*:*:*:*:*
  • OR cpe:/a:gforge:gforge:4.8.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:gforge:gforge:4.5:*:*:*:*:*:*:*
  • OR cpe:/a:gforge:gforge:4.7:rc2:*:*:*:*:*:*
  • AND
  • cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:8066
    P
    DSA-1937 gforge -- insufficient input sanitising
    2014-06-23
    oval:org.mitre.oval:def:13586
    P
    DSA-1937-1 gforge -- insufficient input sanitising
    2014-06-23
    oval:org.debian:def:1937
    V
    insufficient input sanitising
    2009-11-21
    BACK
    gforge gforge 4.5.14
    gforge gforge 4.7 rc2
    gforge gforge 4.8.1
    gforge gforge 4.5
    gforge gforge 4.7 rc2
    debian debian linux 4.0
    debian debian linux 5.0