Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-14912 PoC — cgit 路径遍历漏洞

Source
Associated Vulnerability
Title:cgit 路径遍历漏洞 (CVE-2018-14912)
Description:cgit是一个用C语言编写的用于git存储库的Web前端。 cgit 1.2.1之前版本中的cgit_clone_objects存在目录遍历漏洞。在‘cgit_clone_objects’被打开时,攻击者可通过发送特制的请求利用该漏洞检索任意文件。
Description
cGit < 1.2.1 via cgit_clone_objects has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.
File Snapshot

id: CVE-2018-14912 info: name: cgit < 1.2.1 - Directory Traversal author: 0x_Akoko severity: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.