Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-21972 — CVE-2021-21972 Exploit | Kitploit
Tools/GitHubGitHub/ns-sp4ce/cve-2021-21972
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubns-sp4ce/cve-2021-21972

CVE-2021-21972

CVE-2021-21972 Exploit

View Repository
4991383 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-21972

CVE-2021-21972

Works On

  • VMware-VCSA-all-6.7.0-8217866, VMware-VIM-all-6.7.0-8217866 ✔
  • VMware-VCSA-all-6.5.0-16613358 ✔

For vCenter6.7 U2+

vCenter 6.7U2+ runs the website in memory, so this exploit cannot work for 6.7 u2+.

Needs Testing

  • vCenter 6.5 Linux (VCSA)/Windows Awaiting Testing
  • vCenter 6.7 Linux (VCSA)/Windows Awaiting Testing
  • vCenter 7.0 Linux (VCSA)/Windows Awaiting Testing

Details

  1. The vulnerability is arbitrary file upload.
  2. The vulnerable endpoint is /ui/vropspluginui/rest/services/uploadova, full path (https://domain.com/ui/vropspluginui/rest/services/uploadova).
  3. The tar file in the payload folder in the repository is the default Behinder 3 webshell.

Screenshots

Download Tool

Runtime

3.png

Success

1.png

1.png

Disclaimer

  • The tool is only for security testing and research by security personnel. Any direct or indirect consequences and losses caused by unauthorized testing are the responsibility of the user.
  • The tool is only used for security testing and research by security personnel. Any direct or indirect consequences and losses caused by unauthorized testing are the responsibility of the user.