CVE-2020-23151
09.08.2021, 23:15
rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed directly to the exec function without being escaped.
Vendor | Product | Version |
---|---|---|
rconfig | rconfig | 3.9.5 |
𝑥
= Vulnerable software versions
References