Sploitus

CVE-2019-16663

4 known exploits for CVE-2019-16663

An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.

Affected products
Rconfig
Rconfig
= 3.9.2
Fix
Available
CVSS 2.0
9.0 HIGH
CVSS 3.1
8.8 HIGH
EPSS
97.7% (100th percentile)
Weakness
CWE-78
NVD status
Modified
Published
2019-10-28
CVE-2019-16663 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2019-16663

Proof-of-concept code and exploit modules indexed by Sploitus