CVE-2018-1000533

Source
https://cve.org/CVERecord?id=CVE-2018-1000533
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000533.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-1000533
Published
2018-06-26T16:29:01.883Z
Modified
2026-03-14T09:25:47.374995Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in searchTree function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using search form. This vulnerability appears to have been fixed in 0.7 after commit 87b8c26b023c3fc37f0796b14bb13710f397b322.

References

Affected packages

Git / github.com/klaussilveira/gitlist

Affected ranges

Type
GIT
Repo
https://github.com/klaussilveira/gitlist
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.6.0"
        }
    ]
}

Affected versions

0.*
0.1
0.2
0.3
0.4.0
0.5.0
0.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000533.json"