mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 23:27:33 +02:00
744 B
744 B
CVE-2014-5023
Description
Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkout -b" command.
POC
Reference
- http://hatriot.github.io/blog/2014/06/29/gitlist-rce/
- http://hatriot.github.io/blog/2014/06/29/gitlist-rce/
Github
No PoCs found on GitHub currently.