Update pre-auth-rce-gocd.yaml
parent
3eff5e541d
commit
0ac7e92ac9
|
@ -6,7 +6,6 @@ info:
|
||||||
severity: critical
|
severity: critical
|
||||||
reference: https://twitter.com/wvuuuuuuuuuuuuu/status/1456316586831323140
|
reference: https://twitter.com/wvuuuuuuuuuuuuu/status/1456316586831323140
|
||||||
tags: go,rce,intrusive
|
tags: go,rce,intrusive
|
||||||
description: "An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution."
|
|
||||||
|
|
||||||
requests:
|
requests:
|
||||||
- method: GET
|
- method: GET
|
||||||
|
|
Loading…
Reference in New Issue