
Cloud Vulnerability DB
A community-led vulnerabilities database
A SQL injection vulnerability exists in config.inc.php of rConfig 3.9.5 that allows attackers to access sensitive database information via a crafted GET request to the install/ directory (NVD).
The vulnerability exists in the config.inc.php file within the install/ directory of rConfig version 3.9.5. An attacker can exploit this by sending specially crafted GET requests that contain malicious SQL code, allowing them to manipulate database queries and potentially extract sensitive information from the database (NVD).
Successful exploitation of this vulnerability could allow attackers to access sensitive database information, potentially exposing confidential data stored in the rConfig database (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."