漏洞描述 SolarView Compact6.00包含通过Solar_AiConf.php的跨站点脚本漏洞。攻击者可以在受影响站点的上下文中,在毫无怀疑的用户的浏览器中执行任意脚本。这可使攻击者窃取基于cookie的身份验证凭据并发起其他攻击。
相关漏洞推荐 POC CVE-2022-29298: SolarView Compact 6.00 - Local File Inclusion POC CVE-2022-29299: SolarView Compact 6.00 - 'time_begin' Cross-Site Scripting POC CVE-2022-29301: SolarView Compact 6.00 - 'pow' Cross-Site Scripting POC CVE-2022-29303: SolarView Compact 6.00 - OS Command Injection POC CVE-2022-31373: SolarView Compact 6.00 - Cross-Site Scripting POC CVE-2023-23333: SolarView Compact 6.00 - OS Command Injection POC CVE-2023-29919: SolarView Compact <= 6.00 - Local File Inclusion POC CVE-2022-29303: SolarView Compact conf_mail.php 远程命令执行漏洞 POC CVE-2023-29919: SolarView Compact <= 6.00 - Local File Inclusion POC solarview-compact-xss: SolarView Compact 6.00 - Cross-Site Scripting SolarView Compact CVE-2022-29303命令注入漏洞 SolarView Compact CVE-2022-29299 XSS 漏洞 SolarView Compact through 6.00 命令执行漏洞