### [CVE-2017-1000117](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000117) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen) ### Description A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability. ### POC #### Reference - https://hackerone.com/reports/260005 - https://www.exploit-db.com/exploits/42599/ #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/AnonymKing/CVE-2017-1000117 - https://github.com/GrahamMThomas/test-git-vuln_CVE-2017-1000117 - https://github.com/Jerry-zhuang/CVE-2017-1000117 - https://github.com/Kaulesh01/File-Upload-CTF - https://github.com/M1a0rz/test - https://github.com/Manouchehri/CVE-2017-1000117 - https://github.com/Q2h1Cg/CVE-2017-1000117 - https://github.com/Shadow5523/CVE-2017-1000117-test - https://github.com/VulApps/CVE-2017-1000117 - https://github.com/alilangtest/CVE-2017-1000117 - https://github.com/apogiatzis/temp_proj3 - https://github.com/chenzhuo0618/test - https://github.com/chu1337/CVE-2017-1000117 - https://github.com/cved-sources/cve-2017-1000117 - https://github.com/dfgfdug8df7/some - https://github.com/greymd/CVE-2017-1000117 - https://github.com/ieee0824/CVE-2017-1000117 - https://github.com/ieee0824/CVE-2017-1000117-sl - https://github.com/ikmski/CVE-2017-1000117 - https://github.com/leezp/CVE-2017-1000117 - https://github.com/lnick2023/nicenice - https://github.com/mtrampic/cvedetails_nifi_web_scrape - https://github.com/n0-traces/cve_monitor - https://github.com/nkoneko/CVE-2017-1000117 - https://github.com/qazbnm456/awesome-cve-poc - https://github.com/rootclay/CVE-2017-1000117 - https://github.com/sasairc/CVE-2017-1000117_wasawasa - https://github.com/shogo82148/Fix-CVE-2017-1000117 - https://github.com/siling2017/CVE-2017-1000117 - https://github.com/simith003/demo - https://github.com/takehaya/CVE-2017-1000117 - https://github.com/thelastbyte/CVE-2017-1000117 - https://github.com/tigerszk/ssmjp-100th-message - https://github.com/timwr/CVE-2017-1000117 - https://github.com/vulsio/gost - https://github.com/wuhao939/vulhub - https://github.com/xbl3/awesome-cve-poc_qazbnm456 - https://github.com/yoichi/yoichi.github.io