|
Gitorious contains a flaw in the graphs controller function. The issue is due to the gitorious-mainline/lib/gitorious/git_shell.rb script not sanitizing user-supplied input. With a specially crafted request, a remote attacker can inject arbitrary shell commands.
|