A command injection vulnerability exists in klaussilveira GitList versions 0.6 and earlier, specifically in the searchTree function. The vulnerability is due to insufficient sanitization of user-supplied input, which is passed to a system function. An attacker can exploit this by sending a crafted POST request via the search form, resulting in arbitrary command execution as the PHP user.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact proof-of-concept for CVE-2018-1000533, a remote command execution flaw in GitList 0.6.0 caused by unsafe handling of user-controlled input in the search feature that invokes 'git grep'. The repo contains 4 files: a Python exploit script (poc.py), a Dockerfile and docker-compose.yml to build a vulnerable lab, and a README explaining the bug and reproduction steps. The main exploit logic is in 'poc.py'. It accepts a base URL argument, constructs the target endpoint '/example/tree/a/search', and sends an HTTP POST request with form field 'query' set to '--open-files-in-pager=touch /tmp/success_dddo0;'. This abuses git grep option injection: although the application shell-escapes the query, git still interprets a leading '--...' string as an option. The chosen option causes git to invoke an external pager command, resulting in execution of 'touch /tmp/success_dddo0' on the server. The script is operational but basic: it uses a fixed repository name, fixed route, and fixed payload, and reports only the HTTP status plus instructions to verify file creation. The Dockerfile builds a vulnerable GitList 0.6.0 environment and initializes a sample repository at '/data/example'. The docker-compose file exposes the web service on port 8080. Together, these files make the repository both a runnable lab and an exploit PoC. Overall purpose: demonstrate authenticated/unauthenticated web-reachable RCE against a vulnerable GitList instance via crafted POST data to the search endpoint. The exploit capability is arbitrary command execution as the web server/PHP user; the included payload only creates a marker file, but the primitive could be adapted to run other commands.
This repository contains a single Metasploit module (gitlist_arg_injection.rb) that exploits an argument injection vulnerability (CVE-2018-1000533) in GitList v0.6.0. The exploit leverages improper input validation in the 'escapeshellarg' PHP function, allowing an attacker to inject arbitrary PHP code for execution on the server. The module first checks for a vulnerable GitList instance by looking for a specific string in the HTTP response, then enumerates available repositories, and finally sends a crafted POST request to the '/<repo>/tree/c/search' endpoint with a malicious 'query' parameter. The payload is PHP code, enabling remote code execution as the web server user. The exploit is operational and requires the attacker to know or enumerate a valid repository on the target GitList instance. The only file in the repository is a Ruby script designed for use within the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.