CVE-2020-9425: rConfig <3.9.4 - Sensitive Information Disclosure

CVE-2020-9425: rConfig <3.9.4 - Sensitive Information Disclosure-渗透云记 - 专注于网络安全与技术分享
CVE-2020-9425: rConfig <3.9.4 - Sensitive Information Disclosure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2020-9425: rConfig <3.9.4 – Sensitive Information Disclosure

漏洞描述

rConfig prior to version 3.9.4 is susceptible to sensitive information disclosure. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application does not exit after a redirect is applied, the rest of the page still executes, resulting in the disclosure of cleartext credentials in the response.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享