rconfig.com
http://rconfig.com/ CVE-2021-29006
MEDIUMNuclei
rConfig 3.9.6 - Local File Inclusion
Record summary
CVE-2021-29006 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMrConfig 3.9.6 - Local File InclusionCVSS 6.5
rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.
Impact
Authenticated attackers can read arbitrary files from the server including /etc/passwd, potentially exposing sensitive system information and credentials.
Remediation
Upgrade to rConfig version 3.9.7 or later.
WeaknessesCWE-22
Authorsr3Y3r53
Template tagscve2021cverconfigauthenticatedlfivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:rconfig:rconfig:3.9.6:*:*:*:*:*:*:*
Shodan: http.title:"rConfig"
Shodan: http.title:"rconfig"
FOFA: title="rconfig"
Google: intitle:"rconfig"
https://github.com/mrojz/rconfig-exploit/blob/main/CVE-2021-29006-POC.py https://nvd.nist.gov/vuln/detail/CVE-2021-29006 http://rconfig.com/
Source: ProjectDiscovery
References
3github.com
https://github.com/mrojz/rconfig-exploit/blob/main/CVE-2021-29006-POC.py nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-29006