Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
rConfig SQL注入漏洞
Vulnerability Description
rConfig是一款开源的网络配置管理实用程序。 rConfig 3.9.5版本中存在SQL注入漏洞。远程攻击者可借助‘custom_Location’参数向devices.crud.php脚本发送特制的SQL语句利用该漏洞查看,添加,修改或删除后端数据库中的信息。
CVSS Information
N/A
Vulnerability Type
N/A