Vulnerabilities > Rconfig
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-08-01 | CVE-2023-39108 | Server-Side Request Forgery (SSRF) vulnerability in Rconfig 3.9.4 rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClass.php. | 8.8 |
2023-08-01 | CVE-2023-39109 | Server-Side Request Forgery (SSRF) vulnerability in Rconfig 3.9.4 rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /classes/compareClass.php. | 8.8 |
2023-08-01 | CVE-2023-39110 | Server-Side Request Forgery (SSRF) vulnerability in Rconfig 3.9.4 rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. | 8.8 |
2023-04-15 | CVE-2022-45030 | SQL Injection vulnerability in Rconfig 3.9.7 A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-priv). | 8.8 |
2023-03-27 | CVE-2023-24366 | Unspecified vulnerability in Rconfig 6.8.0 An arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HTTP request. | 6.5 |
2022-11-17 | CVE-2022-44384 | Unrestricted Upload of File with Dangerous Type vulnerability in Rconfig 3.9.6 An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file. | 8.8 |
2021-10-11 | CVE-2021-29005 | Incorrect Default Permissions vulnerability in Rconfig 3.9.6 Insecure permission of chmod command on rConfig server 3.9.6 exists. | 8.8 |
2021-10-11 | CVE-2021-29006 | Path Traversal vulnerability in Rconfig 3.9.6 rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. | 6.5 |
2021-10-11 | CVE-2021-29004 | SQL Injection vulnerability in Rconfig 3.9.6 rConfig 3.9.6 is affected by SQL Injection. | 8.8 |
2021-08-20 | CVE-2020-25351 | Files or Directories Accessible to External Parties vulnerability in Rconfig 3.9.5 An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. | 6.5 |