Логотип exploitDog
bind:CVE-2020-10549
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-10549

Количество 2

Количество 2

nvd логотип

CVE-2020-10549

около 5 лет назад

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-24vx-3r2r-h4mc

около 3 лет назад

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-10549

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVSS3: 9.8
92%
Критический
около 5 лет назад
github логотип
GHSA-24vx-3r2r-h4mc

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

92%
Критический
около 3 лет назад

Уязвимостей на страницу