RULE(RULE ID:332444)

Rule General Information
Release Date: 2021-01-28
Rule Name: rConfig search.crud.php OS Command Injection Vulnerability (CVE-2020-10879)
Severity:
CVE ID:
Rule Protection Details
Description: rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:48241
https://github.com/rconfig/rconfig/commit/3385f906427d228c48b914625136bf620f4ca0a9
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://github.com/rconfig/rconfig/commit/3385f906427d228c48b914625136bf620f4ca0a9