Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-5955

EPSS 86.57% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-5955

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated attacker to add a user to the server via the username and password fields to the rest/user/ URI.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
GitStack 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GitStack是一套基于Windows平台的版本控制系统。 GitStack 2.3.10及之前版本中存在安全漏洞,该漏洞源于程序没有充分的过滤用户的输入。攻击者可通过向rest/user/ URI发送username和password字段利用该漏洞向服务器上添加用户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2018-5955

#POC DescriptionSource LinkShenlong Link
1GitStackRCE漏洞(CVE-2018-5955)EXPhttps://github.com/b0bac/GitStackRCEPOC Details
2一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能https://github.com/YagamiiLight/CerberusPOC Details
3An exploit for CVE-2018-5955 GitStack 2.3.10 Unauthenticated RCEhttps://github.com/MikeTheHash/CVE-2018-5955POC Details
4GitStackRCE漏洞(CVE-2018-5955)EXPhttps://github.com/QianliZLP/GitStackRCEPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-5955

登录查看更多情报信息。

Same Patch Batch · n/a · 2018-01-21 · 7 CVEs total

CVE-2016-10708OpenSSH sshd 安全漏洞
CVE-2017-18046Dasan GPON ONT WiFi Router 缓冲区错误漏洞
CVE-2018-5956ALLIT Zillya! Antivirus 安全漏洞
CVE-2018-5957ALLIT Zillya! Antivirus 安全漏洞
CVE-2018-5958ALLIT Zillya! Antivirus 安全漏洞
CVE-2017-18045JBMC DirectAdmin 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2018-5955

No comments yet


Leave a comment