Record summary

CVE-2021-29006 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMrConfig 3.9.6 - Local File InclusionCVSS 6.5

rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.

Impact

Authenticated attackers can read arbitrary files from the server including /etc/passwd, potentially exposing sensitive system information and credentials.

Remediation

Upgrade to rConfig version 3.9.7 or later.

WeaknessesCWE-22
Authorsr3Y3r53
Template tagscve2021cverconfigauthenticatedlfivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:rconfig:rconfig:3.9.6:*:*:*:*:*:*:*
Shodan: http.title:"rConfig"
Shodan: http.title:"rconfig"
FOFA: title="rconfig"
Google: intitle:"rconfig"

Source: ProjectDiscovery

References

3