Command Execution Vulnerability in rConfig 3.9.2

Command Execution Vulnerability in rConfig 3.9.2

CVE-2019-16662 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.

Learn more about our Cis Benchmark Audit For Server Software.