CVE-2022-29298
- EPSS 89.61%
- Published 12.05.2022 16:15:07
- Last modified 21.11.2024 06:58:52
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
CVE-2021-20662
- EPSS 0.4%
- Published 24.02.2021 12:15:23
- Last modified 21.11.2024 05:46:58
Missing authentication for critical function in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to alter the setting information without the access privileges via unspecified vectors.
CVE-2021-20661
- EPSS 1.22%
- Published 24.02.2021 12:15:23
- Last modified 21.11.2024 05:46:57
Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors.
CVE-2021-20660
- EPSS 0.61%
- Published 24.02.2021 12:15:23
- Last modified 21.11.2024 05:46:57
Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20659
- EPSS 1.57%
- Published 24.02.2021 12:15:22
- Last modified 21.11.2024 05:46:57
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code.
- EPSS 2.14%
- Published 24.02.2021 12:15:22
- Last modified 21.11.2024 05:46:57
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors.
CVE-2021-20657
- EPSS 0.32%
- Published 24.02.2021 12:15:22
- Last modified 21.11.2024 05:46:57
Improper access control vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtain and/or alter the setting information without the access privilege via unspecified vectors.
CVE-2021-20656
- EPSS 0.33%
- Published 24.02.2021 12:15:22
- Last modified 21.11.2024 05:46:57
Exposure of information through directory listing in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtain the information inside the system, such as directories and/or file configurations via unspecified vectors.
- EPSS 73.45%
- Published 14.03.2014 15:55:05
- Last modified 12.04.2025 10:46:40
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.