İçeriğe atla
Noroxi

rconfig kayıtları

rconfig üreticisine ait 45 yayımlanmış kayıt.

Tüm kayıtlar

45 kayıt
  • lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacte

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %77

    rconfig · rconfig8 Mar 2020

  • CVE-2020-10220
    69Bu hafta

    An issue was discovered in rConfig through 3.9.4.

    KritikCVSS 9,8SilahlaştırılmışEPSS %100

    rconfig · rconfig7 Mar 2020

  • CVE-2019-16662
    68Bu hafta

    An issue was discovered in rConfig 3.9.2.

    KritikCVSS 9,8SilahlaştırılmışEPSS %98

    rconfig · rconfig28 Eki 2019

  • CVE-2020-10546
    65Bu hafta

    rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection.

    KritikCVSS 9,8Kavram kanıtıEPSS %87

    rconfig · rconfig4 Haz 2020

  • CVE-2020-10879
    64Bu hafta

    rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is pas

    KritikCVSS 9,8Kavram kanıtıEPSS %84

    rconfig · rconfig23 Mar 2020

  • CVE-2020-13638
    62Bu hafta

    lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation.

    KritikCVSS 9,8Kavram kanıtıEPSS %77

    rconfig · rconfig13 Kas 2020

  • CVE-2019-16663
    60Bu hafta

    An issue was discovered in rConfig 3.9.2.

    YüksekCVSS 8,8Kavram kanıtıEPSS %85

    rconfig · rconfig28 Eki 2019

  • CVE-2019-19509
    56Planlayın

    An issue was discovered in rConfig 3.9.3.

    YüksekCVSS 8,8SilahlaştırılmışEPSS %72

    rconfig · rconfig6 Oca 2020

  • CVE-2020-12255
    51Planlayın

    rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality.

    YüksekCVSS 8,8Kavram kanıtıEPSS %53

    rconfig · rconfig18 May 2020

  • CVE-2020-12259
    50Planlayın

    rConfig 3.9.4 is vulnerable to reflected XSS.

    OrtaCVSS 5,4Kavram kanıtıEPSS %96

    rconfig · rconfig18 May 2020

  • CVE-2020-12256
    50Planlayın

    rConfig 3.9.4 is vulnerable to reflected XSS.

    OrtaCVSS 5,4Kavram kanıtıEPSS %96

    rconfig · rconfig18 May 2020

  • CVE-2020-10547
    50Planlayın

    rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection.

    KritikCVSS 9,8Kavram kanıtıEPSS %37

    rconfig · rconfig4 Haz 2020

  • CVE-2020-10548
    50Planlayın

    rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection.

    KritikCVSS 9,8Kavram kanıtıEPSS %37

    rconfig · rconfig4 Haz 2020

  • CVE-2020-10549
    49Planlayın

    rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection.

    KritikCVSS 9,8Kavram kanıtıEPSS %32

    rconfig · rconfig4 Haz 2020

  • CVE-2019-19207
    42Planlayın

    rConfig 3.9.2 allows devices.php?searchColumn= SQL injection.

    YüksekCVSS 8,8İstismar yokEPSS %23

    rconfig · rconfig21 Kas 2019

  • CVE-2020-23151
    41Planlayın

    rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is

    KritikCVSS 9,8İstismar yokEPSS %6

    rconfig · rconfig9 Ağu 2021

  • CVE-2020-15715
    40Planlayın

    rConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error in the search.crud.ph

    KritikCVSS 9,9İstismar yokEPSS %4

    rconfig · rconfig28 Tem 2020

  • CVE-2022-44384
    37İzleyin

    An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.

    YüksekCVSS 8,8SilahlaştırılmışEPSS %5

    rconfig · rconfig17 Kas 2022

  • CVE-2020-25359
    37İzleyin

    An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6.

    KritikCVSS 9,1İstismar yokEPSS %2

    rconfig · rconfig20 Ağu 2021

  • CVE-2020-12258
    37İzleyin

    rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled.

    KritikCVSS 9,1İstismar yokEPSS %2

    rconfig · rconfig18 May 2020

  • CVE-2020-9425
    36İzleyin

    An issue was discovered in includes/head.inc.php in rConfig before 3.9.4.

    YüksekCVSS 7,5Kavram kanıtıEPSS %19

    rconfig · rconfig20 Mar 2020

  • CVE-2020-13778
    36İzleyin

    rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to lib/ajaxHandlers/ajaxA

    YüksekCVSS 8,8İstismar yokEPSS %4

    rconfig · rconfig19 Eki 2020

  • CVE-2023-39110
    36İzleyin

    rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php.

    YüksekCVSS 8,8Kavram kanıtıEPSS %4

    rconfig · rconfig1 Ağu 2023

  • CVE-2023-39109
    36İzleyin

    rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /classes/co

    YüksekCVSS 8,8Kavram kanıtıEPSS %3

    rconfig · rconfig1 Ağu 2023

  • CVE-2023-39108
    36İzleyin

    rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/co

    YüksekCVSS 8,8Kavram kanıtıEPSS %3

    rconfig · rconfig1 Ağu 2023