Sinapsi eSolar Light Photovoltaic System Monitor contains a flaw that is triggered when input passed via the ip_dominio parameter upon submission to the ping.php script. With a specially crafted HTTP request, a remote attacker can execute arbitrary commands.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
No Vendor Response
OSVDB:
SCADA
Solution
OSVDB is not aware of a solution for this vulnerability.