Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2021-21972 — Nmap 스크립트로 uploadova 엔드포인트를 프로빙하고 취약한 응답을 확인하여 VMware vCenter Server CVE-2021-21972 RCE 취약점을 탐지합니다. | Kitploit
도구/GitHubGitHub/alt3kx/cve-2021-21972
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingRemote Access Tool
GitHubalt3kx/cve-2021-21972

CVE-2021-21972

Nmap 스크립트로 uploadova 엔드포인트를 프로빙하고 취약한 응답을 확인하여 VMware vCenter Server CVE-2021-21972 RCE 취약점을 탐지합니다.

저장소 보기
5415705년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2021-21972 (점검기)

VMware vCenter Server CVE-2021-21972 원격 코드 실행 취약점

이 스크립트는 다음 경로를 기반으로 CVE-2021-21972의 존재 여부를 확인합니다. "/ui/vropspluginui/rest/services/uploadova"에 POST 요청을 보내고 응답 본문(500)에서 "uploadFile"이라는 단어를 찾습니다. 이는 vCenter가 제한 없이 POST를 통해 파일을 수락할 수 있음을 의미합니다.

수동 확인:

# curl -i -s -k -X $'GET' -H $'Host: <target>' -H $'User-Agent: alex666' $'https://<target>/ui/vropspluginui/rest/services/getstatus'
# curl -i -s -k -X $'GET' -H $'Host: <target>' -H $'User-Agent: alex666'$'https://<target>/ui/vropspluginui/rest/services/uploadova'
# curl -i -s -k -X $'POST' -H $'Host: <target>' -H $'User-Agent: alex666' -H $'Content-Type: application/x-www-form-urlencoded' -H $'Content-Length: 0' $'https://<target>/ui/vropspluginui/rest/services/uploadova'

참고 자료:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21972
https://www.vmware.com/security/advisories/VMSA-2021-0002.html

사용법

nmap -p443 --script CVE-2021-21972.nse <target>

출력

---
-- @usage
-- nmap -p443 --script CVE-2021-21972.nse <target>
-- @output
-- PORT    STATE SERVICE
-- 443/tcp open  https
-- | CVE-2021-21972: 
-- |   VULNERABLE:
-- |   vCenter 6.5-7.0 RCE
-- |     State: VULNERABLE (Exploitable)
-- |     IDs:  CVE:CVE-2021-21972
-- |       The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. 
-- |       A malicious actor with network access to port 443 may exploit this issue to execute commands with 
-- |       unrestricted privileges on the underlying operating system that hosts vCenter Server.
-- |     Disclosure date: 2021-02-23
-- |     References:
-- |_      https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21972

화면 녹화

저자

Alex Hernandez aka (@_alt3kx_)

도구 다운로드