Vulnerabilities > Gitlist

DATE CVE VULNERABILITY TITLE RISK
2018-06-26 CVE-2018-1000533 Improper Input Validation vulnerability in Gitlist
klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user.
network
low complexity
gitlist CWE-20
7.5
2014-07-22 CVE-2014-5023 Remote Command Execution vulnerability in GitList
Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkout -b" command.
network
gitlist
6.8
2014-07-22 CVE-2013-7392 Arbitrary Command Execution vulnerability in GitList
Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/.
network
low complexity
gitlist
7.5