Description |
In CVE-2022-29303, a command injection vulnerability in SolarView Compact version 6.00, discovered via conf_mail.php.
In CVE-2022-40881, a command injection vulnerability in SolarView Compact version 6.00, discovered via network_test.php.
This article describes the assessment of command injection vulnerability in SolarView Compact. |
Scope | FortiDAST Scripting Engine updated in version 24.2.0 |
Solution |
Detection against that vulnerability is empowered by the FortiDAST Scripting Engine (FSE).
For reference, a step-by-step guide on how to configure FortiDAST to trigger FSE can be found on Fortinet’s blog: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.