Skip to content

CVE-2014-4511

Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request for a (1) blame, (2) file, or (3) stats page, as demonstrated by requests to blame/master/, master/, and stats/master/.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.8662 (86.6%)
Percentile: 99.4%
EPSS: 2026-05-06

Affects

gitlist:gitlist

Technical description

Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request for a (1) blame, (2) file, or (3) stats page, as demonstrated by requests to blame/master/, master/, and stats/master/.

Published: 7/22/2014, 2:55:09 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam