GForge is reported prone to multiple input validation vulnerabilities that may be exploited to disclose directory listings outside of the designated CVS root directory. The vulnerabilites exist due to a lack of sufficient sanitization performed on user supplied URI parameters. Information that is disclosed in this manner may be used to aid in further attacks that are launched against the target computer.
GForge is reported prone to multiple input validation vulnerabilities that may be exploited to disclose directory listings outside of the designated CVS root directory. The vulnerabilites exist due to a lack of sufficient sanitization performed on user supplied URI parameters. Information that is disclosed in this manner may be used to aid in further attacks that are launched against the target computer.