You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When GitHacker meets Apache/Nginx with folder Indexes enabled, it will
recursively download `.git` folder. GitHacker incorrectly trust the
hyperlink from the Apache/Nginx, that allows to write arbitrary content
into arbitrary file on the GitHacker users machine.
This issue is reported by Justin Steven
<https://twitter.com/justinsteven>. Thanks a lot for his excellent work
and his responsible disclosure.
0 commit comments