Home/Product/rconfig
Product

rconfig

44 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-39110
all versions
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. Th
8.8HIGH
CVE-2023-39109
all versions
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /
8.8HIGH
CVE-2023-39108
all versions
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /
8.8HIGH
CVE-2022-45030
all versions
A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact
8.8HIGH
CVE-2023-24366
all versions
An arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HTTP request
6.5MEDIUM
CVE-2022-44384
all versions
An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.
8.8HIGH
CVE-2021-29006
all versions
rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on th
6.5MEDIUM
CVE-2021-29005
all versions
Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as roo
8.8HIGH
CVE-2021-29004
all versions
rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in My
8.8HIGH
CVE-2020-27466
all versions
An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to execute arbitr
7.8HIGH
CVE-2020-27464
<= 3.9.6
An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrary code via
7.8HIGH
CVE-2020-25359
all versions
An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability
9.1CRITICAL
CVE-2020-25353
all versions
A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed remote au
6.5MEDIUM
CVE-2020-25352
all versions
A stored cross-site scripting (XSS) vulnerability in the /devices.php function inrConfig 3.9.5 has been fixed for version 3.9.6. T
5.4MEDIUM
CVE-2020-25351
all versions
An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote authe
6.5MEDIUM
CVE-2020-23151
all versions
rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path pa
9.8CRITICAL
CVE-2020-23150
all versions
A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database information via a c
7.5HIGH
CVE-2020-23149
all versions
The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection and acces
7.5HIGH
CVE-2020-23148
all versions
The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obta
7.5HIGH
CVE-2020-13638
>= 3.9.0 and < 3.9.7
lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. Th
9.8CRITICAL
CVE-2020-13778
<= 3.9.4
rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to lib/ajaxHand
8.8HIGH
CVE-2020-15715
all versions
rConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error in the sear
9.9CRITICAL
CVE-2020-15714
all versions
rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.cru
8.8HIGH
CVE-2020-15713
all versions
rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.php
8.8HIGH
CVE-2020-15712
all versions
rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a crafted
4.3MEDIUM
CVE-2020-10549
<= 3.9.4
rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are
9.8CRITICAL
CVE-2020-10548
<= 3.9.4
rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are s
9.8CRITICAL
CVE-2020-10547
<= 3.9.4
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes
9.8CRITICAL
CVE-2020-10546
<= 3.9.4
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' pass
9.8CRITICAL
CVE-2020-12256
all versions
rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit th
5.4MEDIUM
CVE-2020-12255
all versions
rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php
8.8HIGH
CVE-2020-12258
all versions
rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse
9.1CRITICAL
CVE-2020-12257
all versions
rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such as a CSRF
8.8HIGH
CVE-2020-12259
all versions
rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit t
5.4MEDIUM
CVE-2020-10879
< 3.9.5
rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parame
9.8CRITICAL
CVE-2020-9425
< 3.9.4
An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext
7.5HIGH
CVE-2020-10221
<= 3.9.4
lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell me
8.8HIGH
CVE-2020-10220
<= 3.9.4
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchCol
9.8CRITICAL
CVE-2019-19585
all versions
An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "r
7.8HIGH
CVE-2019-19509
all versions
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET reques
8.8HIGH
CVE-2019-19372
<= 3.9.3
A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary
7.5HIGH
CVE-2019-19207
all versions
rConfig 3.9.2 allows devices.php?searchColumn= SQL injection.
8.8HIGH
CVE-2019-16663
all versions
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud
8.8HIGH
CVE-2019-16662
all versions
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerS
9.8CRITICAL
threatengine.sh