rConfig ÖÐÁ½¸öÔ¶³Ì´úÂëÖ´ÐÐ 0day ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-11-04·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-16662£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-16663£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÕâÁ½¸ö·ì϶ӰÏìËùÓÐ rConfig °æ±¾£¬Ô̺¬×îа汾3.9.2
·ì϶¸ÅÊö
rConfigÊÇÓÃPHP±àдµÄ¿ªÔ´ÍøÂçÉ豸ÅäÖù¤¾ß£¬Æ¾¾Ý¸ÃÏîÖ÷ÕÅÍøÕ¾£¬rConfig±»ÓÃÓÚÖÎÀí³¬¹ý330Íò¸öÍøÂçÉ豸¡£
°²È«×êÑÐÈËÔ±ÔÚrConfig¹¤¾ßÖз¢ÏÖÁ½¸ö佨¸´µÄ¹Ø¼üRCE·ì϶£¬²¢Åû¶ÁËÓйØPoC¡£ÕâÁ½¸ö·ì϶Ô̺¬ajaxServerSettingsChk.phpÖÐδ¾Éí·ÝÑéÖ¤µÄRCE£¨CVE-2019-16662£©ºÍsearch.crud.phpÖо¹ýÉí·ÝÑéÖ¤µÄRCE£¨CVE-2019-16663£©¡£¹¥»÷Õß¿Éͨ¹ýGET²ÎÊý½Ó¼ûÎļþ²¢ÔÚÖ¸±ê·þÎñÆ÷ÉÏÖ´ÐжñÒâºÅÁî¡£
·ì϶ÑéÖ¤
POC£ºhttps://shells.systems/rconfig-v3-9-2-authenticated-and-unauthenticated-rce-cve-2019-16663-and-cve-2019-16662/¡£
½¨¸´½¨Òé
ĿǰÕâÁ½¸ö·ì϶¾ùδ°ä²¼²¹¶¡¡£½¨ÒéÓû§ÔÚ²¹¶¡°ä²¼Ç°Ò»Ê±´Ó·þÎñÆ÷Öн«Æäɾ³ý¡£
²Î¿¼Á´½Ó
https://shells.systems/rconfig-v3-9-2-authenticated-and-unauthenticated-rce-cve-2019-16663-and-cve-2019-16662/


¾©¹«Íø°²±¸11010802024551ºÅ