Skip to content
Noroxi

gitlist records

4 published records for vendor gitlist.

Researcher profile

Entered KEV
0 · 0%
Weaponized
2 · 50%
Pre-auth RCE
3
With a fix record
25%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

4 records
  • CVE-2018-1000533
    61This week

    klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` functio

    CriticalCVSS 9.8WeaponizedEPSS 73%

    gitlist · gitlistJun 26, 2018

  • Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request

    HighCVSS 7.5WeaponizedEPSS 83%

    gitlist · gitlistJul 22, 2014

  • CVE-2013-7392
    33Monitor

    Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/.

    HighCVSS 7.5Proof of conceptEPSS 8%

    gitlist · gitlistJul 22, 2014

  • CVE-2014-5023
    28Monitor

    Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacha

    MediumCVSS 6.8Proof of conceptEPSS 3%

    gitlist · gitlistJul 22, 2014