CVE-2018-1000533
Last modified
CVE-2018-1000533 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using search form. EPSS estimates a 75.86% chance of exploitation in the next 30 days.
Description
klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using search form. This vulnerability appears to have been fixed in 0.7 after commit 87b8c26b023c3fc37f0796b14bb13710f397b322.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlist | Gitlist | <= 0.6.0 |
References
- https://github.com/klaussilveira/gitlist/commit/87b8c26b023c3fc37f0796b14bb13710f397b322Patch, Third Party Advisory
- https://security.szurek.pl/exploit-bypass-php-escapeshellarg-escapeshellcmd.htmlExploit, Third Party Advisory
- https://github.com/klaussilveira/gitlist/commit/87b8c26b023c3fc37f0796b14bb13710f397b322Patch, Third Party Advisory
- https://security.szurek.pl/exploit-bypass-php-escapeshellarg-escapeshellcmd.htmlExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1000533?
How severe is CVE-2018-1000533?
How do I fix CVE-2018-1000533?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1000527Froxlor version <= 0.9.39.5 contains a PHP Object Injection …
- CVE-2018-1000528GONICUS GOsa version before commit 56070d6289d47ba3f59188859…
- CVE-2018-1000529Grails Fields plugin version 2.2.7 contains a Cross Site Scr…
- CVE-2018-1000530Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-1000531inversoft prime-jwt version prior to commit abb0d479389a2509…
- CVE-2018-1000532beep version 1.3 and up contains a External Control of File …
- CVE-2018-1000534Joplin version prior to 1.0.90 contains a XSS evolving into …
- CVE-2018-1000535lms version <= LMS_011123 contains a Local File Disclosure v…7.5
- CVE-2018-1000536Medis version 0.6.1 and earlier contains a XSS vulnerability…
- CVE-2018-1000537Marlin Firmware Marlin version 1.1.x and earlier contains a …
- CVE-2018-1000538Minio Inc. Minio S3 server version prior to RELEASE.2018-05-…
- CVE-2018-1000539Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347:…
Are you affected by CVE-2018-1000533?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
