rConfig ÖÐÁ½¸öÔ¶³Ì´úÂëÖ´ÐÐ 0day Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-11-04Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-16662£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-16663£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÕâÁ½¸öÎó²îÓ°ÏìËùÓÐ rConfig °æ±¾£¬£¬£¬£¬£¬£¬£¬°üÀ¨×îа汾3.9.2
Îó²î¸ÅÊö
rConfigÊÇÓÃPHP±àдµÄ¿ªÔ´ÍøÂç×°±¸ÉèÖù¤¾ß£¬£¬£¬£¬£¬£¬£¬Æ¾Ö¤¸ÃÏîÄ¿µÄÍøÕ¾£¬£¬£¬£¬£¬£¬£¬rConfig±»ÓÃÓÚÖÎÀíÁè¼Ý330Íò¸öÍøÂç×°±¸¡£¡£¡£¡£¡£¡£
Çå¾²Ñо¿Ö°Ô±ÔÚrConfig¹¤¾ßÖз¢Ã÷Á½¸öδÐÞ¸´µÄÒªº¦RCEÎó²î£¬£¬£¬£¬£¬£¬£¬²¢Åû¶ÁËÏà¹ØPoC¡£¡£¡£¡£¡£¡£ÕâÁ½¸öÎó²î°üÀ¨ajaxServerSettingsChk.phpÖÐδ¾Éí·ÝÑéÖ¤µÄRCE£¨CVE-2019-16662£©ºÍsearch.crud.phpÖоÓÉÉí·ÝÑéÖ¤µÄRCE£¨CVE-2019-16663£©¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýGET²ÎÊý»á¼ûÎļþ²¢ÔÚÄ¿µÄЧÀÍÆ÷ÉÏÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
POC£ºhttps://shells.systems/rconfig-v3-9-2-authenticated-and-unauthenticated-rce-cve-2019-16663-and-cve-2019-16662/¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚÕâÁ½¸öÎó²î¾ùδÐû²¼²¹¶¡¡£¡£¡£¡£¡£¡£½¨ÒéÓû§ÔÚ²¹¶¡Ðû²¼Ç°ÔÝʱ´ÓЧÀÍÆ÷Öн«Æäɾ³ý¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://shells.systems/rconfig-v3-9-2-authenticated-and-unauthenticated-rce-cve-2019-16663-and-cve-2019-16662/


¾©¹«Íø°²±¸11010802024551ºÅ