Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/yaunsky/cve-2021-21972
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubyaunsky/cve-2021-21972

CVE-2021-21972

Exploit for CVE-2021-21972, a remote code execution vulnerability in VMware vCenter Server via arbitrary file upload on port 443.

View Repository
8415 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-21972

Vulnerability Description

cve-2021-21972 is a code execution vulnerability

A malicious attacker with access to port 443 can send a specially crafted request to vCenter Server, ultimately leading to remote arbitrary code execution.

Vulnerability Detection

1、The vulnerability is arbitrary file upload

2、The vulnerable interface is

/ui/vropspluginui/rest/services/uploadova,

full path

https://domain.com/ui/vropspluginui/rest/services/uploadova

Remediation Suggestions

- Upgrade vCenter Server version 7.0 to 7.0.U1c

- Upgrade vCenter Server version 6.7 to 6.7.U3l

- Upgrade vCenter Server version 6.5 to 6.5 U3n

Download Tool