跳转到帖子

SolarView Compact unauthenticated remote command execution vulnerability.

recommended_posts

发布于
  • Members

SolarView Compact unauthenticated remote command execution vulnerability.

Disclosed
05/15/2023
Created
09/06/2023

Description

CONTEC's SolarView Series enables you to monitor and visualize solar power and is only available in Japan. This module exploits a command injection vulnerability on the SolarView Compact `v6.00` web application via vulnerable endpoint `downloader.php`. After exploitation, an attacker will have full access with the same user privileges under which the webserver is running (typically as user `contec`).

Author(s)

Platform

Linux,PHP,Unix

Architectures

php, cmd, armle, x64

Development

  • Source Code
  • History
  • 查看数 699
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…