rConfig ÖÐÁ½¸öÔ¶³Ì´úÂëÖ´ÐÐ 0day ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-11-04

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-16662£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-16663£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÕâÁ½¸ö·ì϶ӰÏìËùÓÐ rConfig °æ±¾£¬£¬£¬£¬£¬£¬£¬Ô̺¬×îа汾3.9.2


·ì϶¸ÅÊö


rConfigÊÇÓÃPHP±àдµÄ¿ªÔ´ÍøÂçÉ豸ÅäÖù¤¾ß£¬£¬£¬£¬£¬£¬£¬Æ¾¾Ý¸ÃÏîÖ÷ÕÅÍøÕ¾£¬£¬£¬£¬£¬£¬£¬rConfig±»ÓÃÓÚÖÎÀí³¬¹ý330Íò¸öÍøÂçÉ豸¡£¡£¡£¡£¡£¡£


°²È«×êÑÐÈËÔ±ÔÚrConfig¹¤¾ßÖз¢ÏÖÁ½¸ö佨¸´µÄ¹Ø¼üRCE·ì϶£¬£¬£¬£¬£¬£¬£¬²¢Åû¶ÁËÓйØPoC¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö·ì϶Ô̺¬ajaxServerSettingsChk.phpÖÐδ¾­Éí·ÝÑéÖ¤µÄRCE£¨CVE-2019-16662£©ºÍsearch.crud.phpÖо­¹ýÉí·ÝÑéÖ¤µÄRCE£¨CVE-2019-16663£©¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýGET²ÎÊý½Ó¼ûÎļþ²¢ÔÚÖ¸±ê·þÎñÆ÷ÉÏÖ´ÐжñÒâºÅÁî¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


POC£ºhttps://shells.systems/rconfig-v3-9-2-authenticated-and-unauthenticated-rce-cve-2019-16663-and-cve-2019-16662/¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



½¨¸´½¨Òé


ĿǰÕâÁ½¸ö·ì϶¾ùδ°ä²¼²¹¶¡¡£¡£¡£¡£¡£¡£½¨ÒéÓû§ÔÚ²¹¶¡°ä²¼Ç°Ò»Ê±´Ó·þÎñÆ÷Öн«Æäɾ³ý¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://shells.systems/rconfig-v3-9-2-authenticated-and-unauthenticated-rce-cve-2019-16663-and-cve-2019-16662/