E20-7u391
CVSS:
9.0 (AV:N/AC:L/Au:S/C:C/I:C/A:C)
False Positive:
t
Variants:
6
Year:
2019
Description
An OS Command Injection exists in rConfig 3.9.3 and prior versions as a result of no sanitization of user supplied data. The parameter processed in ajaxArchiveFiles.php is then used as a command line argument within a privileged command. By sending a crafted path parameter to /lib/ajaxHandlers/ajaxArchiveFiles.php path, a remote authenticated attacker may execute arbitrary OS commands as a superuser.
CVE
References
MSB
BID
ExploitDB
Secunia
Security Tracker
Metasploit
ZDI
OSVDB
{}