.. / CVE-2018-1000533

Exploit for GitList < 0.6.0 Remote Code Execution (CVE-2018-1000533)

Description:

klaussilveira GitList version <= 0.6 contains a passing incorrectly sanitized input via the searchTree function that can result in remote code execution.

Nuclei Template

View the template here CVE-2018-1000533.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2018/CVE-2018-1000533.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2018-1000533
https://github.com/klaussilveira/gitlist/commit/87b8c26b023c3fc37f0796b14bb13710f397b322
https://github.com/superlink996/chunqiuyunjingbachang
https://github.com/vulhub/vulhub/tree/master/gitlist/CVE-2018-1000533
https://security.szurek.pl/exploit-bypass-php-escapeshellarg-escapeshellcmd.html