Vulnerabilities
Vulnerable Software
Rconfig:  >> Rconfig  Security Vulnerabilities
A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potentially download files. NOTE: the discoverer later reported that there was not a "fully working exploit.
CVSS Score
7.5
EPSS Score
0.002
Published
2019-11-28
rConfig 3.9.2 allows devices.php?searchColumn= SQL injection.
CVSS Score
8.8
EPSS Score
0.07
Published
2019-11-21
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.
CVSS Score
9.8
EPSS Score
0.945
Published
2019-10-28
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.
CVSS Score
8.8
EPSS Score
0.939
Published
2019-10-28


Contact Us

Shodan ® - All rights reserved