← All CVEs

CVE-2008-5517

high · 7.5

The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related to (1) git_snapshot and (2) git_object.

7.5
CVSS
11.9%
EPSS (exploit prob.)
96th
EPSS percentile
2009-01-13
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
gitgit1.5.0
gitgit1.5.0
gitgit1.5.0
gitgit1.5.0
gitgit1.5.0.1
gitgit1.5.0.2
gitgit1.5.0.3
gitgit1.5.0.4
gitgit1.5.0.5
gitgit1.5.0.6
gitgit1.5.0.7
gitgit1.5.1
gitgit1.5.1.1
gitgit1.5.1.2
gitgit1.5.1.3
gitgit1.5.1.4
gitgit1.5.1.5
gitgit1.5.1.6
gitgit1.5.2
gitgit1.5.2.1
gitgit1.5.2.2
gitgit1.5.2.3
gitgit1.5.2.4
gitgit1.5.2.5
gitgit1.5.3
gitgit1.5.3
gitgit1.5.3
gitgit1.5.3
gitgit1.5.3.1
gitgit1.5.3.2
gitgit1.5.3.3
gitgit1.5.3.4
gitgit1.5.3.5
gitgit1.5.3.6
gitgit1.5.3.7
gitgit1.5.3.8
gitgit1.5.4
gitgit1.5.4
gitgit1.5.4
gitgit1.5.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-5517