CVE-2019-19585
An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig specific Apache configuration" update, apache has high privileges for some binaries. This can be exploited by an attacker to bypass local security restrictions.
- Rconfig
- = 3.9.3
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 5.7% (93th percentile)
- Weakness
- CWE-269
- NVD status
- Modified
- Published
- 2020-01-06
CVE-2019-19585 at NVD
9 known exploits for CVE-2019-19585
Proof-of-concept code and exploit modules indexed by Sploitus
exploits-rconfig
rConfig 3.9.4 - (searchField) Unauthenticated Root Remote Code Execution Exploit
rConfig 3.9.4 searchField Remote Code Execution
rConfig 3.9.4 - searchField Unauthenticated Root Remote Code Execution
rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
Rconfig 3.x Chained Remote Code Execution Exploit
Rconfig 3.x Chained Remote Code Execution
Rconfig 3.x Chained Remote Code Execution
Exploit for OS Command Injection in Rconfig