
CVE-2021-21978 exp
CVE-2021-21978 RCE exp
Affected versions VMware View Planner Harness 4.X
Similar to CVE-2021-21978, this vulnerability allows uploading arbitrary files without authentication, and achieving remote code execution by modifying the built-in py script. It is worth noting that commands are executed in the docker container, not directly on the system.
Usage:
go run CVE-2021-21978.go -h <target ip> -c <cmd>
