HIGH
An issue was discovered in rConfig 3.9.2
Published Oct 28, 2019
8.8
HIGHCVSS 3.1
EPSS 84.70%
Description
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://drive.google.com/open?id=1XmR2MSMb3cKARFk3XxmPkwz6GhAP1JxL x_refsource_MISCExploitThird Party Advisory
- https://drive.google.com/open?id=1kQGmboKfwob4RwlMjnv6ER2Za1GUptOi x_refsource_MISCExploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-7228 Advisory
- https://gist.github.com/mhaskar/e7e454c7cb0dd9a139b0a43691e258a0 x_refsource_MISCExploitThird Party Advisory
- https://rconfig.com/download x_refsource_MISCProduct
- https://shells.systems/rconfig-v3-9-2-authenticated-and-unauthenticated-rce-cve-2019-16663-and-cve-2019-16662/ x_refsource_MISCExploitTechnical DescriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://drive.google.com/open?id=1XmR2MSMb3cKARFk3XxmPkwz6GhAP1JxL | x_refsource_MISCExploitThird Party Advisory | |
| https://drive.google.com/open?id=1kQGmboKfwob4RwlMjnv6ER2Za1GUptOi | x_refsource_MISCExploitThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-7228 | Advisory | |
| https://gist.github.com/mhaskar/e7e454c7cb0dd9a139b0a43691e258a0 | x_refsource_MISCExploitThird Party Advisory | |
| https://rconfig.com/download | x_refsource_MISCProduct | |
| https://shells.systems/rconfig-v3-9-2-authenticated-and-unauthenticated-rce-cve-2019-16663-and-cve-2019-16662/ | x_refsource_MISCExploitTechnical DescriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 28, 2019
Updated Aug 5, 2024
Reserved Sep 21, 2019
Link CVE-2019-16663
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-7228 Assigner mitre
Published Oct 28, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-7228