rConfig 3.9 漏洞列表
共找到 4 个与 rConfig 3.9 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2019-16662: rConfig 3.9.2 - Remote Code Execution POC
rConfig 3.9.2 is susceptible to a remote code execution vulnerability. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution. -
CVE-2020-10220: rConfig 3.9 - SQL Injection POC
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter. -
CVE-2020-10546: rConfig 3.9.4 - SQL Injection POC
rConfig 3.9.4 and previous versions have unauthenticated compliancepolicies.inc.php SQL injection. Because nodes' passwords are stored in cleartext by default, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices. -
CVE-2023-39108: rConfig 3.9.4 - Server-Side Request Forgery POC
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.