Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-35064 PoC — VIAware 安全漏洞

Source
Associated Vulnerability
Title:VIAware 安全漏洞 (CVE-2021-35064)
Description:Kramer Electronics VIAware是以色列克莱默电子(Kramer Electronics)公司的一套无线演示协作软件解决方案。 KramerAV VIAWare存在安全漏洞,该漏洞允许攻击者通过错误配置 sudo 来提升权限。
Description
Kramer VIAware, all tested versions, allow privilege escalation and remote code execution due to misconfigured sudo permissions. Attackers can execute arbitrary system commands remotely if the web interface is accessible, due to vulnerabilities in the handling of privileged operations through ajaxPages/writeBrowseFilePathAjax.php and improper sudoers configurations.
File Snapshot

id: CVE-2021-35064 info: name: Kramer VIAware - Privilege Escalation and Remote Code Execution ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.