KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view