Command Execution Vulnerability in rConfig 3.9.2

Command Execution Vulnerability in rConfig 3.9.2

CVE-2019-16663 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.

Learn more about our Web Application Penetration Testing UK.