github.com
https://github.com/Timorlover/SolarView_Compact_6.0_rce_via_network_test.php CVE-2022-40881
CRITICALNuclei
contec solarview_compact Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2022-40881 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
solarview_compactBrowse contec / solarview_compact | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubyilin1203/CVE-2022-40881Repository PoCby yilin1203Stars: 2Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALSolarView 6.00 - Remote Command ExecutionCVSS 9.8
SolarView Compact 6.00 is vulnerable to a command injection via network_test.php.
Impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands on the target system.
Remediation
Apply the latest patch or upgrade to a non-vulnerable version of SolarView.
WeaknessesCWE-77
AuthorsFor3stCo1d
Template tagscvecve2022solarviewrcelficontecvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:h:contec:solarview_compact:-:*:*:*:*:*:*:*
Shodan: http.favicon.hash:"-244067125"
Shodan: cpe:"cpe:2.3:h:contec:solarview_compact"
https://github.com/Timorlover/SolarView_Compact_6.0_rce_via_network_test.php https://github.com/advisories/GHSA-wx3r-88rg-whxq https://nvd.nist.gov/vuln/detail/CVE-2022-40881 https://github.com/KayCHENvip/vulnerability-poc https://github.com/Threekiii/Awesome-POC
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-40881