GitStack through version 2.3.10 contains a vulnerability in which user-controlled input to the rest/user/ URI is not properly filtered. This allows an unauthenticated attacker to add arbitrary users to the server by supplying crafted username and password fields, bypassing authentication controls.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module targeting GitStack (up to v2.3.10) via its unauthenticated REST API. The module exploits CVE-2018-5955, allowing attackers to perform several administrative actions without authentication. Capabilities include listing users and repositories, creating new users, adding users to all repositories, and deleting users. The module interacts with the target over HTTP, specifically using the '/rest/user/' and '/rest/repository/' endpoints. The code is written in Ruby and is structured as a typical Metasploit module, with actions mapped to REST API operations. This exploit is operational and can be used to gain unauthorized administrative access to vulnerable GitStack instances.
This repository contains a single Metasploit module (gitstack_rce.rb) that exploits a remote code execution vulnerability (CVE-2018-5955) in GitStack up to version 2.3.10 on Windows. The exploit leverages unsanitized arguments passed to an exec call in the GitStack web interface, allowing an attacker to execute arbitrary PowerShell code on the target system. The module interacts with several REST API endpoints to enumerate and manipulate repositories and users, and ultimately triggers the vulnerability via a specially crafted HTTP request to /web/index.php. The payload is fully customizable through Metasploit, supporting a range of post-exploitation actions. The code is mature, weaponized, and part of the Metasploit framework, making it easy to use and adapt for penetration testing or red teaming. The only file present is the exploit module itself, written in Ruby.
This repository contains a Python 3 exploit script (exploit.py) targeting CVE-2018-5955, an unauthenticated remote code execution vulnerability in GitStack 2.3.10 on Windows. The exploit automates the process of user and repository creation (if needed), enables the web interface, and abuses a vulnerability to write a PHP webshell (exploit.php) to the target's filesystem. The script then provides an interactive shell for arbitrary command execution via the webshell, detects the target OS, and can spawn a reverse shell (using bash for Linux or PowerShell for Windows) to an attacker-specified host and port. The README.md provides usage instructions and describes the exploit's features. The main attack vector is network-based, exploiting the HTTP API of GitStack. Several fingerprintable endpoints are used, including REST API paths and the webshell location. The repository is operational in maturity, providing a working exploit with interactive and reverse shell capabilities.
This repository is a Python-based web vulnerability scanner named Cerberus. It is designed to automate the detection of a wide range of web application vulnerabilities, including SQL injection, XSS, command injection, file inclusion, and SSRF. The tool supports both single-target and batch scanning (via file input or subdomain enumeration), and can also collect and use proxy IPs to bypass WAFs or IP bans. It features middleware fingerprinting and targeted exploitation for specific platforms (ThinkPHP, phpMyAdmin, Tomcat, Weblogic, Wordpress, Dedecms), with hardcoded exploits for known CVEs (e.g., CVE-2018-5955, CVE-2018-12613, CVE-2018-11759). The scanner can detect WAFs and attempt known bypasses, and it generates scan reports. The main entry point is 'cerberus.py', which orchestrates scanning based on command-line arguments. The codebase is modular, with core logic for payload management, proxy handling, subdomain brute-forcing, and vulnerability exploitation. Numerous endpoints are fingerprinted, including public proxy sources, file paths for LFI/RFI, and SSRF targets. The repository is operational and suitable for real-world vulnerability assessment of web applications.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.