Update pre-auth-rce-gocd.yaml
parent
3eff5e541d
commit
0ac7e92ac9
|
@ -6,7 +6,6 @@ info:
|
|||
severity: critical
|
||||
reference: https://twitter.com/wvuuuuuuuuuuuuu/status/1456316586831323140
|
||||
tags: go,rce,intrusive
|
||||
description: "An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution."
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
|
|
Loading…
Reference in New Issue