CVE-2019-16662
CRITICAL EXPLOITED NUCLEIrconfig 3.9.2 - OS Command Injection via ajaxServerSettingsChk.php rootUname Parameter
Title source: llmExploitation Summary
CVE-2019-16662 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 4 public exploits from researchers including Metasploit, Askar, mhaskar, including a Metasploit module exploits/unix/webapp/rconfig_install_cmd_exec.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated command injection vulnerability in rConfig via the `ajaxServerSettingsChk.php` file. It supports both in-memory and dropper-based payloads for Unix/Linux targets.
Description
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.
Exploits (4)
This Metasploit module exploits an unauthenticated command injection vulnerability in rConfig via the `ajaxServerSettingsChk.php` file. It supports both in-memory and dropper-based payloads for Unix/Linux targets.
This exploit targets a remote code execution vulnerability in rConfig 3.9.2 by injecting a PHP payload via the `rootUname` parameter in an unauthenticated request to `/install/lib/ajaxHandlers/ajaxServerSettingsChk.php`. The payload establishes a reverse shell to a specified IP and port.
This repository contains a functional Python exploit for CVE-2019-16662, targeting rConfig 3.9.2. The exploit leverages an unauthenticated remote code execution vulnerability by injecting a reverse shell payload via the `ajaxServerSettingsChk.php` endpoint.
This Metasploit module exploits an unauthenticated command injection vulnerability in rConfig versions 3.9.2 and prior via the `ajaxServerSettingsChk.php` file. It allows arbitrary command execution as the web server user by injecting commands through the `rootUname` parameter.
Nuclei Templates (1)
http.title:"rconfig"
title="rconfig"
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H