module
VMware View Planner Unauthenticated Log File Upload RCE
| Disclosed | Created |
|---|---|
| Mar 2, 2021 | Mar 18, 2021 |
Disclosed
Mar 2, 2021
Created
Mar 18, 2021
Description
This module exploits an unauthenticated log file upload within the
log_upload_wsgi.py file of VMWare View Planner 4.6 prior to 4.6
Security Patch 1.
Successful exploitation will result in RCE as the apache user inside
the appacheServer Docker container.
log_upload_wsgi.py file of VMWare View Planner 4.6 prior to 4.6
Security Patch 1.
Successful exploitation will result in RCE as the apache user inside
the appacheServer Docker container.
Authors
Platform
Python
Architectures
python
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.