header-logo
Suggest Exploit
vendor:
ViewGit
by:
Matthew R. Bucci
6,1
CVSS
MEDIUM
Persistent arbitrary script injection (XSS)
79
CWE
Product Name: ViewGit
Affected Version From: ViewGit 0.0.6
Affected Version To: ViewGit 0.0.6
Patch Exists: YES
Related CWE: CVE-2013-2294
CPE: a:viewgit:viewgit:0.0.6
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: CentOS 6.3 with PHP 5.3.3 and Apache 2.2.15
2013

Vulnerability Report

ViewGit contains multiple persistent arbitrary script injection (XSS) vulnerabilities in its 'Shortlog' and 'Heads' tables. These vulnerabilities are triggered by malicious data inserted via the branch or tag systems of git by one of the users of the repository.

Mitigation:

In order to inject arbitrary script, attackers must have the ability to manipulate the git repository. Specifically, the attacker must be able to create branches or tags.
Source

Exploit-DB raw data: