Filtered by vendor Rconfig Subscriptions
Filtered by product Rconfig Subscriptions
Total 44 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-10220 1 Rconfig 1 Rconfig 2020-03-28 9.8 Critical
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.
CVE-2019-19207 1 Rconfig 1 Rconfig 2019-11-26 8.8 High
rConfig 3.9.2 allows devices.php?searchColumn= SQL injection.
CVE-2019-16662 1 Rconfig 1 Rconfig 2019-11-07 9.8 Critical
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.
CVE-2019-16663 1 Rconfig 1 Rconfig 2019-10-29 8.8 High
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.