Unrated severityNVD Advisory· Published Jul 22, 2014· Updated Jun 17, 2026
CVE-2014-4511
CVE-2014-4511
Description
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request for a (1) blame, (2) file, or (3) stats page, as demonstrated by requests to blame/master/, master/, and stats/master/.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5Patches
Vulnerability mechanics
References
6- hatriot.github.io/blog/2014/06/29/gitlist-rce/nvdExploit
- packetstormsecurity.com/files/127281/Gitlist-0.4.0-Remote-Code-Execution.htmlnvdExploit
- packetstormsecurity.com/files/127364/Gitlist-Unauthenticated-Remote-Command-Execution.htmlnvdExploit
- www.exploit-db.com/exploits/33929nvdExploit
- www.exploit-db.com/exploits/33990nvdExploit
- groups.google.com/forum/nvd
News mentions
0No linked articles in our index yet.