--------------------------------------------------------------------------- Various Vulnerabilities in GForge --------------------------------------------------------------------------- Author: Jose Antonio Coret (Joxean Koret) Date: 2005 Location: Basque Country --------------------------------------------------------------------------- Affected software description: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ GForge - 4.5 (Current) GForge has tools to help your team collaborate, like message forums and mailing lists; tools to create and control access to Source Code Management repositories like CVS and Subversion. GForge automatically creates a repository and controls access to it depending on the role settings of the project. Web : http://gforge.org/ --------------------------------------------------------------------------- A) Cross Site Scripting Vulnerabilities ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 1.- In the Forum Module: http://[target]/forum/forum.php?forum_id="> http://[target]/forum/forum.php?group_id="> (NOTE: The group_id parameter is ALWAYS vulnerable.) 2.- In the Task Module: http://[target]/pm/task.php?func=detailtask&project_task_id=">