Exploitation Summary
EIP tracks 2 public exploits for CVE-2013-4490.
PoCs published by Metasploit, Brandon Knight, including Metasploit module exploits/multi/http/gitlab_shell_exec.
AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in GitLab-shell versions prior to 1.7.4 by injecting malicious commands into SSH key additions. It requires valid credentials to authenticate and add an SSH key, which is then used to execute arbitrary commands.
Description
The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.
Exploits (2)
This Metasploit module exploits a command injection vulnerability in GitLab-shell versions prior to 1.7.4 by injecting malicious commands into SSH key additions. It requires valid credentials to authenticate and add an SSH key, which is then used to execute arbitrary commands.
This Metasploit module exploits a command injection vulnerability in GitLab-shell (CVE-2013-4490) by injecting malicious commands into SSH key additions. It requires valid credentials and targets versions prior to 1.7.4.