Vulnerability index

Browse CVEs

44 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2020-12256EPSS 96% rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbi… Rconfig No fix yet Fix from $1,6002020-05-18 CRITICAL 9.1 CVE-2020-12258 rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPS… Rconfig Mitigation only Fix from $2,3002020-05-18 HIGH 8.8 CVE-2020-12257 rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such as a CSRF token. An attacker… Rconfig No fix yet Fix from $1,9502020-05-18 MEDIUM 5.4 CVE-2020-12259EPSS 96% rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability b… Rconfig Mitigation only Fix from $1,6002020-05-18 CRITICAL 9.8 CVE-2020-10879EPSS 84% rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed direc… Rconfig 3.9.5+ Fix from $2,3002020-03-23 HIGH 7.5 CVE-2020-9425EPSS 19% An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a … Rconfig 3.9.4+ Fix from $1,9502020-03-20 HIGH 8.8 CVE-2020-10221 KEVEPSS 37% lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the… Rconfig after 3.9.4 Fix from $1,9502020-03-08 CRITICAL 9.8 CVE-2020-10220EPSS 100% An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter. Rconfig after 3.9.4 Fix from $2,3002020-03-07 HIGH 8.8 CVE-2019-19509EPSS 72% An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFil… Rconfig No fix yet Fix from $1,9502020-01-06 HIGH 7.8 CVE-2019-19585EPSS 6% An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig specific Apa… Rconfig No fix yet Fix from $1,9502020-01-06 HIGH 7.5 CVE-2019-19372 A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potent… Rconfig after 3.9.3 Fix from $1,9502019-11-28 HIGH 8.8 CVE-2019-19207EPSS 23% rConfig 3.9.2 allows devices.php?searchColumn= SQL injection. Rconfig No fix yet Fix from $1,9502019-11-21 CRITICAL 9.8 CVE-2019-16662EPSS 98% An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php beca… Rconfig No fix yet Fix from $2,3002019-10-28 HIGH 8.8 CVE-2019-16663EPSS 85% An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the ca… Rconfig No fix yet Fix from $1,9502019-10-28