FAIL › dossier
rConfig
VENDORDossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2020-10221 | high | rConfig suffered an OS command injection flaw allowing remote attackers to execute arbitrary system commands via the fileName POST parameter. |
| 2021-11-03 | CVE-2020-10221 | high | rConfig suffered an OS command injection flaw allowing remote attackers to execute arbitrary system commands via the fileName POST parameter. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
rConfig's OS command injection flaw was widely condemned as a severe security failure allowing remote attackers to execute arbitrary commands, with no positive coverage found in the provided sources.
severe condemnation of the OS command injection vulnerability allowing remote attackers to execute arbitrary commands.
"rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter."
neutral; source is unrelated to rConfig/CVE-2020-10221.
neutral; source is unrelated to rConfig/CVE-2020-10221.
neutral; source is unrelated to rConfig/CVE-2020-10221.
neutral; source is unrelated to rConfig/CVE-2020-10221.
neutral; source is unrelated to rConfig/CVE-2020-10221.
neutral; source is unrelated to rConfig/CVE-2020-10221.