mrojz/rconfig-exploit

mrojz/rconfig-exploit

Releases0
Stars2

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM

An arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HTTP request.

8.8 HIGH9 HIGH

Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on server.

6.5 MEDIUM4 MEDIUM

rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.

8.8 HIGH6.5 MEDIUM

rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL server is not set and the Mysql server is the same as rConfig, an attacker may successfully upload a webshell to the server and access it remotely.