Vulnerability Details CVE-2014-4511
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request for a (1) blame, (2) file, or (3) stats page, as demonstrated by requests to blame/master/, master/, and stats/master/.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.813
EPSS Ranking 99.1%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2014-4511
-
cpe:2.3:a:gitlist:gitlist:-
-
cpe:2.3:a:gitlist:gitlist:0.1
-
cpe:2.3:a:gitlist:gitlist:0.2
-
cpe:2.3:a:gitlist:gitlist:0.3
-
cpe:2.3:a:gitlist:gitlist:0.4.0