CVE-2022-44354
Description
Unrestricted File Upload vulnerability in SolarView Compact 4.0,5.0 at /Solar_Image.php can allow attackers to get a Remote Code Execution on the vulnerable host via upload crafted php file.
POC
navigate to /Solar_Image.php
upload any php file and caputre the request
update the
userfile
andupfilename
parameters like this:
send the request and navigate to /images/background/shell.php?cmd=ls
Last updated