CVE-2008-6188

EUVD-2008-6158
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
Affected Products (NVD)
VendorProductVersion
gforgegforge
𝑥
≤ 4.6rc1
gforgegforge
3.0
gforgegforge
3.1
gforgegforge
3.2
gforgegforge
3.3
gforgegforge
3.21
gforgegforge
4.5
gforgegforge
4.5.11
gforgegforge
4.5.14
gforgegforge
4.5.16
gforgegforge
4.5.19
gforgegforge
4.6
gforgegforge
4.6_b2:_b2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gforge
dapper
ignored
gutsy
ignored
hardy
ignored
intrepid
ignored
jaunty
not-affected
karmic
not-affected
lucid
not-affected
maverick
not-affected
natty
dne
oneiric
dne