There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.
SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server.
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
SolarView Compact < 6.00 is vulnerable to Directory Traversal.
SolarView Compact 7.0 is vulnerable to Cross-site Scripting (XSS) via /networktest.php.