VYPR
Vendor

Gitlist

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2014-4511Jul 22, 2014
    risk 0.10cvss epss 0.83

    Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request for a (1) blame, (2) file, or (3) stats page, as demonstrated by requests to blame/master/, master/, and stats/master/.

  • CVE-2018-1000533CriJun 26, 2018
    risk 0.09cvss 9.8epss 0.73

    klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using search form. This…

  • CVE-2013-7392Jul 22, 2014
    risk 0.04cvss epss 0.08

    Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/.

  • CVE-2014-5023Jul 22, 2014
    risk 0.03cvss epss 0.03

    Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkout -b" command.