Showing 5 vulnerabilities on this page for solarview_compact

Signals CISA KEV Ransomware Nuclei
contec vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.

CWE-94Oct 27, 2023
CVSS9.8v3.1EPSS0.807%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

contec solarview_compact Incorrect Default Permissions

SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.

CWE-276May 23, 20231 related artifact
CVSS9.8v3.1EPSS60.2%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

contec solarview_compact Improper Neutralization of Special Elements used in a Command ('Command Injection')

There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.

CWE-77Feb 6, 20231 related artifact
CVSS9.8v3.1EPSS99.3%PoCs6SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

contec solarview_compact Unrestricted Upload of File with Dangerous Type

SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.

CWE-434Nov 29, 2022
CVSS9.8v3.1EPSS2.13%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

contec solarview_compact Improper Neutralization of Special Elements used in a Command ('Command Injection')

SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php

CWE-77Nov 17, 20221 related artifact
CVSS9.8v3.1EPSS29.5%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX