CVE-2022-40881
CRITICAL EXPLOITED IN THE WILD NUCLEISolarView Compact 6.00 - Command Injection
Title source: llmExploitation Summary
CVE-2022-40881 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including yilin1203. A Nuclei detection template is also available.
AI-analyzed exploit summary This PoC exploits CVE-2022-40881, a command injection vulnerability in SolarView Compact. It sends a crafted POST request to '/network_test.php' with a payload that injects commands to read '/etc/passwd'.
Description
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
Exploits (1)
This PoC exploits CVE-2022-40881, a command injection vulnerability in SolarView Compact. It sends a crafted POST request to '/network_test.php' with a payload that injects commands to read '/etc/passwd'.
Nuclei Templates (1)
http.favicon.hash:"-244067125" || cpe:"cpe:2.3:h:contec:solarview_compact"
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H