.. / CVE-2022-0415

Exploit for Gogs <0.12.6 - Remote Command Execution (CVE-2022-0415)

Description:

Gogs before 0.12.6 is susceptible to remote command execution via the uploading repository file in GitHub repository gogs/gogs. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

Nuclei Template

View the template here CVE-2022-0415.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-0415.yaml
Copy

References:

https://github.com/cokeBeer/go-cves
https://github.com/bfengj/CTF
https://huntr.dev/bounties/b4928cfe-4110-462f-a180-6d5673797902
https://nvd.nist.gov/vuln/detail/CVE-2022-0415
https://github.com/gogs/gogs/commit/0fef3c9082269e9a4e817274942a5d7c50617284