rConfig 3.9.4 漏洞列表
共找到 2 个与 rConfig 3.9.4 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2020-10546: rConfig 3.9.4 - SQL Injection POC
rConfig 3.9.4 and previous versions have unauthenticated compliancepolicies.inc.php SQL injection. Because nodes' passwords are stored in cleartext by default, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices. -
CVE-2023-39108: rConfig 3.9.4 - Server-Side Request Forgery POC
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.