Логотип exploitDog
bind:CVE-2020-10547
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-10547

Количество 2

Количество 2

nvd логотип

CVE-2020-10547

больше 5 лет назад

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-m2x2-97x9-744w

больше 3 лет назад

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-10547

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVSS3: 9.8
90%
Высокий
больше 5 лет назад
github логотип
GHSA-m2x2-97x9-744w

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

90%
Высокий
больше 3 лет назад

Уязвимостей на страницу