packetstormsecurity.com
http://packetstormsecurity.com/files/171613/rconfig-3.9.7-SQL-Injection.html CVE-2022-45030
HIGH
rconfig 3.9.7 - Sql Injection (Authenticated)
Record summary
CVE-2022-45030 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-priv).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2025 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBrconfig 3.9.7 - Sql Injection (Authenticated)ExploitDB exploitby azhenNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-45030 rconfig.com
https://www.rconfig.com/downloads/rconfig-3.9.7.zip