CVE-2008-0167
Last modified
CVE-2008-0167 is a vulnerability of currently unknown severity. The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.. EPSS estimates a 0.73% chance of exploitation in the next 30 days.
Description
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gforge | Gforge | 4.5.14 |
References
- http://secunia.com/advisories/30088Vendor Advisory
- http://secunia.com/advisories/30286Vendor Advisory
- http://secunia.com/advisories/30088Vendor Advisory
- http://secunia.com/advisories/30286Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-0167?
How severe is CVE-2008-0167?
How do I fix CVE-2008-0167?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-0159SQL injection vulnerability in index.php in eggBlog 3.1.0 an…
- CVE-2008-0162misc.c in splitvt 1.6.6 and earlier does not drop group priv…
- CVE-2008-0163Linux kernel 2.6, when using vservers, allows local users to…
- CVE-2008-0164Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2008-0165Cross-site request forgery (CSRF) vulnerability in Ikiwiki b…
- CVE-2008-0166OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-ba…7.5
- CVE-2008-0169Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiw…
- CVE-2008-0171regex/v4/perl_matcher_non_recursive.hpp in the Boost regex l…
- CVE-2008-0172The get_repeat_type function in basic_regex_creator.hpp in t…
- CVE-2008-0173SQL injection vulnerability in Gforge 4.6.99 and earlier all…
- CVE-2008-0174GE Fanuc Proficy Real-Time Information Portal 2.6 and earlie…9.8
- CVE-2008-0175Unrestricted file upload vulnerability in GE Fanuc Proficy R…
Are you affected by CVE-2008-0167?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
