Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Argument injection vulnerability in syntax-highlighting.sh in cgit 9.0.3 and earlier allows remote authenticated users with permissions to add files to execute arbitrary commands via the --plug-in argument to the highlight command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
cgit ‘syntax-highlighting.sh’远程命令注入漏洞
Vulnerability Description
cgit是一个用C语言编写的用于git存储库的Web前端。 cgit 9.0.3和较早版本中的syntax-highlighting.sh中存在参数注入漏洞。远程认证攻击者利用该漏洞通过“--plug-in”参数传送到高亮显示命令,以添加文件权限执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A