Sploitus

CVE-2020-10221

4 known exploits for CVE-2020-10221

lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.

Affected products
Rconfig
Rconfig
≤ 3.9.4
Fix
Available
CVSS 2.0
9.0 HIGH
CVSS 3.1
8.8 HIGH
EPSS
80.2% (100th percentile)
Weakness
CWE-78
NVD status
Analyzed
Published
2020-03-08
CVE-2020-10221 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2020-10221

Proof-of-concept code and exploit modules indexed by Sploitus