Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed directly to the exec function without being escaped.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
rConfig 操作系统命令注入漏洞
Vulnerability Description
rConfig是一款开源的网络配置管理实用程序。 rConfig 3.9.5版本存在操作系统命令注入漏洞,该漏洞源于rConfig路径参数直接传递给 exec 函数而不会被转义。 攻击者可利用该漏洞通过向lib/ajaxHandlers/ajaxArchiveFiles.php 发送精心设计的 GET 请求来进行命令注入。
CVSS Information
N/A
Vulnerability Type
N/A