Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/kooroshrz/cve-2020-10977
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubkooroshrz/cve-2020-10977

CVE-2020-10977

Exploit for "GitLab Instance" Arbitrary server file read vulnerability

View Repository
426 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Python Exploit for gitlab private instance arbitrary file read

At the date of 03/23/2020, a vulnerability report with its PoC was released in hackerone by William Bowling
With this vulnerability we can read any world readable files (with permission 444 or more) on the gitlab server like /etc/passwd and so on... (worldreadable files only)\

root@kitploit:~
Notice that you should be authenticated user

I've tested it on gitlab version 21.9.0 (ubuntu 18.04) but it's OS independent

exploit-db

Many thanks to exploit-db team for publishing this exploit
https://www.exploit-db.com/exploits/48431

Credit

Many thanks to William Bowling
vulnerability disclosed by : William Bowling of Biteable, a.k.a vakzz
https://hackerone.com/reports/827052

Download Tool