Sploitus

CVE-2019-19509

13 known exploits for CVE-2019-19509

An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the exec function without filtering, which can lead to command execution.

Affected products
Rconfig
Rconfig
= 3.9.3
Fix
Available
CVSS 2.0
9.0 HIGH
CVSS 3.1
8.8 HIGH
EPSS
71.6% (99th percentile)
Weakness
CWE-78
NVD status
Modified
Published
2020-01-06
CVE-2019-19509 at NVD
Authoritative description, scoring and affected products

13 known exploits for CVE-2019-19509

Proof-of-concept code and exploit modules indexed by Sploitus