vendor:
Gitlist
by:
drone and Brandon Perry
N/A
CVSS
N/A
Remote Command Execution
78
CWE
Product Name: Gitlist
Affected Version From: 0.4.0
Affected Version To: 0.4.0
Patch Exists: NO
Related CWE: CVE-2014-4511
CPE: a:gitlist:gitlist:0.4.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix
2014
Gitlist Unauthenticated Remote Command Execution
This module exploits an unauthenticated remote command execution vulnerability in version 0.4.0 of Gitlist. The problem exists in the handling of an specially crafted file name when trying to blame it.
Mitigation:
No known mitigation or remediation for this vulnerability