Vulnerabilities > Lars Hjemli > Cgit > 0.7.2

DATE CVE VULNERABILITY TITLE RISK
2013-08-09 CVE-2013-2117 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in the cgit_parse_readme function in ui-summary.c in cgit before 0.9.2, when a readme file is set to a filesystem path, allows remote attackers to read arbitrary files via a ..
4.3
2012-11-11 CVE-2012-4548 Remote Command Injection vulnerability in cgit 'syntax-highlighting.sh'
Argument injection vulnerability in syntax-highlighting.sh in cgit 9.0.3 and earlier allows remote authenticated users with permissions to add files to execute arbitrary commands via the --plug-in argument to the highlight command.
network
lars-hjemli
6.0
2012-10-10 CVE-2012-4465 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Lars Hjemli Cgit
Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 and earlier allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via an empty username in the "Author" field in a commit.
network
low complexity
lars-hjemli CWE-119
6.5
2011-08-03 CVE-2011-2711 Cross-Site Scripting vulnerability in Lars Hjemli Cgit
Cross-site scripting (XSS) vulnerability in the print_fileinfo function in ui-diff.c in cgit 0.9.0.2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the filename associated with the rename hint.
3.5