CVE-2023-39110
- EPSS 76.85%
- Veröffentlicht 01.08.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 08:14:45
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.
CVE-2023-39109
- EPSS 74.83%
- Veröffentlicht 01.08.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 08:14:44
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of ...
CVE-2023-39108
- EPSS 74.83%
- Veröffentlicht 01.08.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 08:14:44
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of ...
CVE-2022-45030
- EPSS 0.05%
- Veröffentlicht 15.04.2023 02:15:07
- Zuletzt bearbeitet 06.02.2025 16:15:30
A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-priv).
CVE-2023-24366
- EPSS 0.33%
- Veröffentlicht 27.03.2023 21:15:11
- Zuletzt bearbeitet 19.02.2025 18:15:22
An arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HTTP request.
CVE-2022-44384
- EPSS 48.69%
- Veröffentlicht 17.11.2022 17:15:13
- Zuletzt bearbeitet 29.04.2025 15:15:51
An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2021-29006
- EPSS 20.59%
- Veröffentlicht 11.10.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:30
rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.
- EPSS 0.05%
- Veröffentlicht 11.10.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:30
Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on server.
CVE-2021-29004
- EPSS 1.64%
- Veröffentlicht 11.10.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:30
rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL server is not set and the Mysql server is the same as rConfig, an attacker may successfully upload a webshell to the...
CVE-2020-27464
- EPSS 1.03%
- Veröffentlicht 20.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:21:13
An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrary code via a crafted ZIP file.