|
|||
Rule General Information |
---|
Release Date: | 2021-01-21 | |
Rule Name: | rConfig search.crud.php Command Injection Vulnerability (CVE-2019-16663) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | A command injection vulnerability has been reported in rConfig Network Device Configuration Tool. The vulnerability is due to insufficient input validation in the search.crud.php. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server. Successful exploitation could result in arbitrary command execution with the web server privilege on the target system. | |
Impact: | An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software. | |
Affected OS: | Windows, Linux, Others | |
Reference: | https://drive.google.com/open?id=1XmR2MSMb3cKARFk3XxmPkwz6GhAP1JxL https://drive.google.com/open?id=1kQGmboKfwob4RwlMjnv6ER2Za1GUptOi https://gist.github.com/mhaskar/e7e454c7cb0dd9a139b0a43691e258a0 https://rconfig.com/download |
|
Solutions |
---|
The vendors have released upgrade patches to fix vulnerabilities, please visit: https://rconfig.com |