VYPR
Unrated severityNVD Advisory· Published Jul 22, 2014· Updated Jun 17, 2026

CVE-2014-4511

CVE-2014-4511

Description

Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request for a (1) blame, (2) file, or (3) stats page, as demonstrated by requests to blame/master/, master/, and stats/master/.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Gitlist/Gitlist5 versions
    cpe:2.3:a:gitlist:gitlist:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:gitlist:gitlist:*:*:*:*:*:*:*:*range: <=0.4.0
    • cpe:2.3:a:gitlist:gitlist:0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gitlist:gitlist:0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gitlist:gitlist:0.3:*:*:*:*:*:*:*
    • (no CPE)range: <0.5.0

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.