KRAMER VIAware through August 2021... CVE-2021-36356

10.0 AV AC AU C I A
发布: 2021-08-31
修订: 2024-11-21

KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an incomplete fix for CVE-2019-17124.

0%
当前有2条漏洞利用/PoC
当前有1条受影响产品信息