Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the (1) dir parameter to controller.php or (2) dir_name parameter to controlleroo.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gforge | Gforge | 3.1 (including) | 3.1 (including) |
Gforge | Gforge | 3.2 (including) | 3.2 (including) |
Gforge | Gforge | 3.3 (including) | 3.3 (including) |
Gforge | Gforge | 3.21 (including) | 3.21 (including) |