CVE-2020-23148
- EPSS 1.62%
- Veröffentlicht 09.08.2021 23:15:06
- Zuletzt bearbeitet 21.11.2024 05:13:36
The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive information via a crafted POST request.
CVE-2020-13638
- EPSS 76.6%
- Veröffentlicht 13.11.2020 20:15:16
- Zuletzt bearbeitet 21.11.2024 05:01:39
lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.
- EPSS 4.39%
- Veröffentlicht 19.10.2020 13:15:13
- Zuletzt bearbeitet 21.11.2024 05:01:50
rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to lib/ajaxHandlers/ajaxAddTemplate.php or lib/ajaxHandlers/ajaxEditTemplate.php.
CVE-2020-15715
- EPSS 4.2%
- Veröffentlicht 28.07.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:06:05
rConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error in the search.crud.php script. An attacker could exploit this vulnerability using the nodeId parameter.
CVE-2020-15714
- EPSS 2.79%
- Veröffentlicht 28.07.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:06:05
rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow the attacker to view, add, modify, or delete informa...
CVE-2020-15713
- EPSS 2.79%
- Veröffentlicht 28.07.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:06:04
rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.php script using the sortBy parameter, which could allow the attacker to view, add, modify, or delete information in the ba...
CVE-2020-15712
- EPSS 1.56%
- Veröffentlicht 28.07.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:04
rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a crafted request to the ajaxGetFileByPath.php script containing hexadecimal encoded "dot dot" sequences (%2f..%2f) in the path pa...
CVE-2020-10549
- EPSS 32.12%
- Veröffentlicht 04.06.2020 04:15:13
- Zuletzt bearbeitet 21.11.2024 04:55:33
rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devi...
CVE-2020-10548
- EPSS 37.73%
- Veröffentlicht 04.06.2020 04:15:13
- Zuletzt bearbeitet 21.11.2024 04:55:33
rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devic...
CVE-2020-10547
- EPSS 33.27%
- Veröffentlicht 04.06.2020 04:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:33
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monito...