Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via newline characters in a filename.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
cgit CRLF注入漏洞
Vulnerability Description
cgit是一个用C语言编写的用于git存储库的Web前端。 cgit 0.12之前版本的ui-shared.c文件中的‘cgit_print_http_headers’函数中存在CRLF注入漏洞。远程攻击者可借助文件名中的换行符利用该漏洞以‘写入资源库权限’注入任意HTTP头,实施HTTP响应拆分攻击或跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A