Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-1000117 PoC — Git 命令注入漏洞

Source
Associated Vulnerability
Title:Git 命令注入漏洞 (CVE-2017-1000117)
Description:A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.
Description
Experiment of CVE-2017-1000117
Readme
# CVE-2017-1000117-sl
Experiment of CVE-2017-1000117

## usage

```
$ git clone --recursive https://github.com/ieee0824/CVE-2017-1000117-sl.git
```
File Snapshot

[4.0K] /data/pocs/68f07487a562bb4bc7642a73663f2f0b26469a9c ├── [ 645] Dockerfile ├── [ 92] Gemfile ├── [ 148] README.md ├── [1.2M] sl.tar.gz └── [4.0K] subs └── [4.0K] dummy-app 2 directories, 4 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →