
PoC for CVE-2025-34030 sar2html 'plot' parameter RCE
CVSS: 10.0 Critical
Vulnerability: OS Command Injection
Programming Language: PHP
Exploit Code: Python
References:
sar2html version <= 3.2.1 contains an unauthenticated OS Command Injection vulnerability via the plot parameter in index.php (index.php?plot=; <command>) the output of the vulnerability is displayed in the application's interface after execution, "select # host" contains command output.
