cpe:/a:gforge:gforge:4.5.19 CVE-2008-6189 2009-02-19T13:30:00.420-05:00 2017-08-16T21:29:06.693-04:00 7.5 NETWORK LOW NONE PARTIAL PARTIAL PARTIAL http://nvd.nist.gov 2009-02-20T10:19:00.000-05:00 ALLOWS_OTHER_ACCESS SECUNIA 32217 XF gforge-topusers-sql-injection(45802) CONFIRM http://gforge.org/tracker/index.php?func=detail&aid=5552&group_id=1&atid=105 SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php.