Vulnerability in Apache Configuration of FusionForge Affected by User Script Execution
CVE-2014-0468
Currently unrated
What is CVE-2014-0468?
The vulnerability in FusionForge arises from a flawed configuration of the Apache web server, which permits the execution of potentially harmful scripts uploaded by users in their raw source control management (SCM) repositories, such as SVN, Git, and Bzr. This flaw could lead to unauthorized access and execution of code on the server, posing significant security risks for deployments of FusionForge versions prior to 5.3+20140506.
Affected Version(s)
fusionforge 0 < 5.3+20140506